CVE-2026-4212
8.8D-Link · NAS Devices (DNS/DNR series)
A stack-based buffer overflow in the Downloads_Schedule_Info function of the download_mgr.cgi script allows remote authenticated attackers to execute arbitrary code.
Executive summary
A critical stack-based buffer overflow vulnerability in various D-Link NAS devices allows authenticated attackers to execute arbitrary code or crash the system.
Vulnerability
The vulnerability resides in the Downloads_Schedule_Info function within the download_mgr.cgi file. An attacker can supply a malicious, overly long f_idx parameter to cause a stack-based buffer overflow, which can lead to remote code execution or a denial of service.
Business impact
Successful exploitation of this vulnerability could lead to a total compromise of the affected D-Link NAS device, resulting in unauthorized access to sensitive stored data or complete system failure. Given the CVSS score of 8.8, this poses a high risk to business continuity and data confidentiality. The ability to execute arbitrary code remotely allows an attacker to establish persistence within the network or exfiltrate private files.
Remediation
Immediate Action: Monitor the D-Link support portal for firmware updates addressing this flaw and apply them to all affected NAS units as soon as they become available.
Proactive Monitoring: Review web access logs for suspicious POST requests directed at /cgi-bin/download_mgr.cgi containing unusually long f_idx parameters.
Compensating Controls: Restrict access to the NAS management interface to trusted internal IP addresses using firewall rules to prevent unauthorized remote access to the vulnerable CGI script.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the researcher's technical write-up.
Analyst recommendation
The presence of a public proof-of-concept elevates the risk of this vulnerability significantly. Organizations utilizing the affected D-Link NAS devices must prioritize the implementation of network-level access controls to isolate these devices from external threats. Administrators should monitor vendor channels for the release of a corrective patch and ensure it is deployed immediately upon availability to prevent potential exploitation.
More D-Link CVEs
Sources
Originally found and disclosed by pjqwudi (VulDB User), per the CVE Program record.
- VDB-351123 | D-Link DNS-1550-04 download_mgr.cgi Downloads_Schedule_Info stack-based overflow Vulnerability database entry
- VDB-351123 | CTI Indicators (IOB, IOC, IOA)
- Submit #770442 | D-Link DNS-120/202L/315L/320/320L/320LW/321/322L/323/325/326/327L/326/340L/343/345/726-4/1100-4/1200-05 Third-party advisory
- Exploit / PoC
- dlink.com