CVE-2026-5213Disclosure(dlink / dnr-202l)

MEDIUMCVSS 7.4 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dnr-202l systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_adduser_to_session of the file /cgi-bin/account_mgr.cgi. This manipulation of the argument read_list causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnr-202l
  • dnr-202l_firmware
  • dnr-326
  • dnr-326_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-01)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dnr-202ldnr-202l_firmwarednr-326dnr-326_firmwaredns-1100-4dns-1100-4_firmwaredns-120dns-1200-05dns-1200-05_firmwaredns-120_firmware

1 version affected across 40 products

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-31: 2Mentions · 2026-04-01: 3PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-04-01: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-3104-01
Signal classification3 categories
Disclosure
360.0%
Exploit
120.0%
General
120.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure2
2026-04-013
Disclosure1Exploit1General1
Full discourse5 posts
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting D-Link DNS-120 and other products (CVE-2026-5213) https://vuldb.com/vuln/354350

    Post summary

    The post announces a new vulnerability (CVE-2026‑5213) affecting D‑Link DNS‑120 and related devices, linking to a VUldb entry for further details.

    0000182
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5213 A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS… https://www.cve.org/CVERecord?id=CVE-2026-5213

    Post summary

    The post announces CVE‑2026‑5213 affecting a range of D‑Link routers but provides no additional technical, exploit, or patch details.

    00000160
    56.9K followersView on X
  • dbugs@ptdbugs
    Exploit

    D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow CVE: CVE-2026-5213 PT-Identifier: PT-2026-29268 Vendor: D-link Product: DNS-120 CVSS: 8.7 Credits: Ziyue Xie (VulDB User) Description: A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_adduser_to_session of the file /cgi-bin/account_mgr.cgi. This manipulation of the argument read_list causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5213 • https://vuldb.com/vuln/354350 • https://vuldb.com/vuln/354350/cti • https://vuldb.com/submit/780437 • https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_168/168.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The post announces that CVE‑2026‑5213, a stack‑based overflow in D‑Link DNS‑120 series, has a publicly disclosed exploit, with PoC code hosted on GitHub, though no active exploitation or patch details are mentioned.

    00000120
    781 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-5213 - High A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345,... https://www.thehackerwire.com/vulnerability/CVE-2026-5213/ https://t.co/nUW56EQp4I

    Post summary

    The tweet announces a high‑severity CVE against multiple D‑Link DNS firmware models and links to a third‑party article, but offers no PoC, exploit code, active exploitation evidence, patch, or detailed technical data.

    0000047
    163 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5213: HIGH] Critical stack-based buffer overflow vulnerability found in specific D-Link models. Attack possible remotely via manipulated argument. Stay secure and update now!#cve,CVE-2026-5213,#cybersecurity https://cvefind.com/CVE-2026-5213

    Post summary

    The tweet announces a critical stack‑based buffer overflow in certain D‑Link models, notes a remote attack vector via manipulated arguments, and urges users to update, but it does not provide PoC, exploit details, or patch specifics.

    0000053
    617 followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdnr-202l---
OSdlinkdnr-202l_firmware---
HWdlinkdnr-326---
OSdlinkdnr-326_firmware---
HWdlinkdns-1100-4---
OSdlinkdns-1100-4_firmware---
HWdlinkdns-120---
HWdlinkdns-1200-05---
OSdlinkdns-1200-05_firmware---
OSdlinkdns-120_firmware---
HWdlinkdns-1550-04---
OSdlinkdns-1550-04_firmware---
HWdlinkdns-315l---
OSdlinkdns-315l_firmware---
HWdlinkdns-320---
OSdlinkdns-320_firmware---
HWdlinkdns-320l---
OSdlinkdns-320l_firmware---
HWdlinkdns-320lw---
OSdlinkdns-320lw_firmware---
HWdlinkdns-321---
OSdlinkdns-321_firmware---
HWdlinkdns-322l---
OSdlinkdns-322l_firmware---
HWdlinkdns-323---
OSdlinkdns-323_firmware---
HWdlinkdns-325---
OSdlinkdns-325_firmware---
HWdlinkdns-326---
OSdlinkdns-326_firmware---
HWdlinkdns-327l---
OSdlinkdns-327l_firmware---
HWdlinkdns-340l---
OSdlinkdns-340l_firmware---
HWdlinkdns-343---
OSdlinkdns-343_firmware---
HWdlinkdns-345---
OSdlinkdns-345_firmware---
HWdlinkdns-726-4---
OSdlinkdns-726-4_firmware---

Explore more