Vulnerability Intelligence Report
D-Link DNS-1550-04 account_mgr.cgi cgi_adduser_to_session stack-based overflow
CVE-2026-5213
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_adduser_to_session of the file /cgi-bin/account_mgr.cgi. This manipulation of the argument read_list causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-121 ↗Stack-based Buffer Overflow
CWE-119 ↗Memory Corruption
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| D-Link | DNS-120 | 20260205 (affected) |
| D-Link | DNR-202L | 20260205 (affected) |
| D-Link | DNS-315L | 20260205 (affected) |
| D-Link | DNS-320 | 20260205 (affected) |
| D-Link | DNS-320L | 20260205 (affected) |
| D-Link | DNS-320LW | 20260205 (affected) |
| D-Link | DNS-321 | 20260205 (affected) |
| D-Link | DNR-322L | 20260205 (affected) |
| D-Link | DNS-323 | 20260205 (affected) |
| D-Link | DNS-325 | 20260205 (affected) |
| D-Link | DNS-326 | 20260205 (affected) |
| D-Link | DNS-327L | 20260205 (affected) |
| D-Link | DNR-326 | 20260205 (affected) |
| D-Link | DNS-340L | 20260205 (affected) |
| D-Link | DNS-343 | 20260205 (affected) |
| D-Link | DNS-345 | 20260205 (affected) |
| D-Link | DNS-726-4 | 20260205 (affected) |
| D-Link | DNS-1100-4 | 20260205 (affected) |
| D-Link | DNS-1200-05 | 20260205 (affected) |
| D-Link | DNS-1550-04 | 20260205 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.715%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulDB · Researcher · Switzerland |
| Reserved | 2026-03-31T10:29:35 |
| Published | 2026-03-31T20:15:18 |
| Last Updated | 2026-04-01T13:41:31 |
Community Chatter & Buzz