CVE-2026-4209
D-Link
- Published
- 16 March 2026
- Last modified
- 17 June 2026
- CVSS
- 2.1 v4.0
- Severity
- low
- EPSS
- 4.5% (91th pct)
- CISA KEV
- Not listed
- NVD status
- Analyzed
- Weaknesses
- CWE-74, CWE-77
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description
A vulnerability was identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected is the function cgi_create_import_users/cgi_user_batch_create/cgi_user_set_quota/cgi_user_del/cgi_user_modify/cgi_group_set_quota/cgi_group_modify/cgi_group_add/cgi_user_add/cgi_get_modify_group_info/cgi_chg_admin_pw of the file /cgi-bin/account_mgr.cgi. The manipulation leads to command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 4.5% probability of exploitation activity in the next 30 days, placing it in the top decile of all scored CVEs.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| DNR-202L | D-Link | unknown | <= 2026-02-05 |
| DNR-326 | D-Link | unknown | <= 1.40b03, <= 2026-02-05 |
References
- https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_148/148.md exploit
- https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_149/149.md exploit
- https://vuldb.com/?ctiid.351120
- https://vuldb.com/?id.351120 third-party
- https://vuldb.com/?submit.770429 third-party
- https://vuldb.com/?submit.770430 third-party
- https://vuldb.com/?submit.770431 third-party
- https://vuldb.com/?submit.770432 third-party
- https://vuldb.com/?submit.770433 third-party
- https://vuldb.com/?submit.770434 third-party
- https://vuldb.com/?submit.770435 third-party
- https://vuldb.com/?submit.770436 third-party
- https://vuldb.com/?submit.770437 third-party
- https://vuldb.com/?submit.770438 third-party
- https://www.dlink.com/
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.