PatchSiren cyber security CVE debrief
CVE-2026-5212 D-Link CVE debrief
A vulnerability has been found in multiple D-Link devices up to 20260205. This issue affects the function Webdav_Upload_File of the file /cgi-bin/webdav_mgr.cgi. The manipulation of the argument f_file leads to stack-based buffer overflow. The attack is possible to be carried out remotely. This vulnerability allows for remote exploitation and could lead to unauthorized access or control of the device.
- Vendor
- D-Link
- Product
- DNS-120
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-31
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-03-31
- Advisory updated
- 2026-07-24
Who should care
Users of affected D-Link devices should prioritize patching this vulnerability, as it allows for remote exploitation and could lead to unauthorized access or control of the device. IT administrators, security teams, and operators of D-Link devices are particularly concerned, as they need to assess their exposure, apply patches, and monitor for potential exploitation attempts.
Technical summary
The vulnerability is a stack-based buffer overflow in the Webdav_Upload_File function of the /cgi-bin/webdav_mgr.cgi file. This occurs when the f_file argument is manipulated in a way that exceeds the buffer's capacity, potentially allowing an attacker to execute arbitrary code remotely. The vulnerability affects multiple D-Link devices, including DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, and DNS-1550-04 up to 20260205.
Defensive priority
High
Recommended defensive actions
- Apply patches or updates provided by D-Link to address the vulnerability.
- Implement network segmentation to limit the spread of potential attacks.
- Monitor network traffic for suspicious activity related to affected devices.
- Consider replacing unsupported or end-of-life devices with supported models.
- Restrict access to the web management interface to trusted networks or users.
- Review and update incident response plans to include procedures for handling potential exploitation of this vulnerability.
- Conduct a thorough review of network configurations and device deployments to identify and mitigate potential exposure.
Evidence notes
The CVE record was published on 2026-03-31T21:16:33.890Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and CVE record. The vulnerability affects multiple D-Link devices up to 20260205. Evidence is limited to public sources and may not reflect the full scope or impact of the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5212 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5212
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5212 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5212
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_166/166.md
[email protected] - Exploit, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/780435
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/submit/780436
[email protected] - Third Party Advisory, VDB Entry
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://vuldb.com/vuln/354348
[email protected] - Third Party Advisory, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/354348/cti
[email protected] - Permissions Required, VDB Entry
-
Source reference
Unverified legacy reference
URL: https://www.dlink.com/
[email protected] - Product
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.