CVE-2026-8260Disclosure(dlink / dcs-935l)

HIGHCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch dlink dcs-935l systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dcs-935l
  • dcs-935l_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-11); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
dcs-935ldcs-935l_firmware

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-10: 1Mentions · 2026-05-11: 3Mentions · 2026-05-12: 1Mentions · 2026-05-22: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-12: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-05-12: 1Active Exploitation · 2026-05-11: 1Patch / Workaround · 2026-05-11: 2Technical Details · 2026-05-11: 3Technical Details · 2026-05-12: 105-1005-1105-1205-22
Signal classification5 categories
Disclosure
233.3%
Active Exploitation
116.7%
Exploit
116.7%
General
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-101
Disclosure1
2026-05-113
Active Exploitation1Exploit1General1
2026-05-121
PoC1
2026-05-221
Disclosure1
Full discourse6 posts
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for D-Link DCS-935L (CVE-2026-8260) https://vuldb.com/vuln/362557

    Post summary

    A new vulnerability (CVE-2026-8260) with increased severity for the D-Link DCS-935L has been disclosed, with a reference to the vulnerability database entry.

    0102096
    2.3K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en productos D-Link ❗ CVE-2026-8260 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-d-link-3/ https://t.co/Sck7w55Sul

    Post summary

    A short tweet announcing a new vulnerability in D-Link products (CVE‑2026‑8260) and providing a link to a more detailed article.

    00010122
    6.7K followersView on X
  • Entity@0x2ed3bb60
    Exploit

    🚨 CVE-2026-8260: Buffer overflow in D-Link DCS-935L ≤1.10.01. HNAP Service exploitable remotely via AdminPassword. Public exploit live. Isolate devices, disable HNAP, or patch now. https://0x2ed3bb60.xyz/threat/e8d1d6291140a59d

    Post summary

    The post announces a publicly available buffer overflow exploit for D-Link DCS-935L and urges users to patch or disable HNAP to mitigate the active threat.

    0001065
    7 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼ #DLink: disponibile #PoC per lo sfruttamento della CVE-2026-8260, presente nel prodotto #DCS-935L Rischio: 🟠 Tipologia: 🔸 Remote Code Execution 🔸 Privilege Escalation 🔗 https://www.acn.gov.it/portale/w/d-link-poc-pubblico-per-lo-sfruttamento-della-cve-2026-8260 🔄 Aggiornamenti disponibili 🔄 https://t.co/76WTHwtB5W

    Post summary

    The tweet announces a publicly available Proof of Concept for CVE‑2026‑8260 affecting DLink DCS‑935L, highlighting RCE and privilege escalation, with no evidence of active exploitation or patch information.

    00000106
    611 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8260 A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the com… https://www.cve.org/CVERecord?id=CVE-2026-8260

    Post summary

    The post merely identifies a CVE affecting a D‑Link device, specifying the vulnerable file and function, but provides no evidence of a PoC, exploit, active exploitation, patch, or debunking.

    00000172
    57.5K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    D-Link DCS-935L CVE-2026-8260: Active buffer overflow exploit lets attackers execute arbitrary code, potentially affecting thousands of devices. Patch now to prevent full compromise. #NerdieNews #CyberSecurity #InfoSec #Vulnerability https://t.co/dZlW5PQyvK

    Post summary

    CVE‑2026‑8260, a buffer overflow affecting thousands of D‑Link DCS‑935L devices, is being actively exploited with arbitrary code execution; a patch is now available to prevent full compromise.

    0000045
    63 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdcs-935l---
OSdlinkdcs-935l_firmware---

Explore more