Medium severity4.3NVD Advisory· Published Mar 31, 2026· Updated Apr 29, 2026
CVE-2026-5215
CVE-2026-5215
Description
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_get_ipv6 of the file /cgi-bin/network_mgr.cgi. Such manipulation leads to improper access controls. The exploit is publicly available and might be used.
Affected products
20Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_170/170.mdnvdExploitThird Party Advisory
- vuldb.com/submit/780440nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/354351nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/354351/ctinvdPermissions RequiredVDB Entry
- www.dlink.comnvdProduct
News mentions
0No linked articles in our index yet.