PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5211 D-Link CVE debrief

A stack-based buffer overflow vulnerability exists in the UPnP functionality of multiple D-Link DNS products. The vulnerability is caused by improper handling of the f_dir argument in the UPnP_AV_Server_Path_Del function of the /cgi-bin/app_mgr.cgi file. This allows remote unauthenticated attackers to execute arbitrary code on affected devices. The affected products include D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, and DNS-1550-04. The vulnerability has a CVSS score of 7.4 and is classified as HIGH severity. Exploitation of this vulnerability could lead to unauthorized code execution, potentially allowing attackers to gain control over affected systems.

Vendor
D-Link
Product
DNS-120
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-31
Original CVE updated
2026-07-24
Advisory published
2026-03-31
Advisory updated
2026-07-24

Who should care

Administrators and users of the affected D-Link DNS products should prioritize patching this vulnerability to prevent potential exploitation. The affected products include D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, and DNS-1550-04. Operators, platform administrators, vulnerability management teams, and security teams should review and act on this vulnerability.

Technical summary

The vulnerability is caused by a stack-based buffer overflow in the UPnP_AV_Server_Path_Del function of the /cgi-bin/app_mgr.cgi file. The function does not properly validate the f_dir argument, allowing remote attackers to overflow the buffer and potentially execute arbitrary code. The vulnerability has a CVSS score of 7.4 and is classified as HIGH severity. The affected products are D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, and DNS-1550-04. Exploitation of this vulnerability could lead to unauthorized code execution, potentially allowing attackers to gain control over affected systems.

Defensive priority

High

Recommended defensive actions

  • Apply patches or updates provided by the vendor to vulnerable systems
  • Restrict access to the /cgi-bin/app_mgr.cgi file
  • Monitor network traffic for suspicious activity
  • Implement a web application firewall to detect and prevent attacks
  • Conduct regular vulnerability assessments and penetration testing
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was reported by an unknown researcher and published on March 31, 2026. The CVE record was published on March 31, 2026, and last modified on July 24, 2026. The NVD entry is currently Analyzed. Evidence of exploitation has not been confirmed, but defenders should verify system logs for suspicious activity related to UPnP functionality. Limited source detail is available; defenders should exercise caution and verify information with official sources.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-03-31T20:16:29.873Z and has not been modified since then.