CVE-2026-5211 describes a high-severity stack-based buffer overflow (CVSS 8.8) affecting numerous D-Link DNS and DNR series network-attached storage (NAS) devices, including firmware up to 20260205. The vulnerability resides in the UPnP_AV_Server_Path_Del function within /cgi-bin/app_mgr.cgi, allowing a remote attacker with low privileges to trigger the flaw by manipulating the f_dir argument. Exploitation requires low attack complexity and no user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. While an exploit has been publicly published, there is currently no evidence of active exploitation in the wild, nor is it listed on the CISA KEV catalog or major exploit databases, though it has received minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dnr-202l_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dnr-326_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dns-1100-4_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dns-120_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dns-1200-05_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.