CVE-2026-5215 identifies an improper access controls vulnerability within the cgi_get_ipv6 function of the /cgi-bin/network_mgr.cgi file, impacting numerous D-Link DNS and DNR series network storage devices up to firmware version 20260205. This vulnerability carries a CVSSv3.1 score of 4.3 (MEDIUM), allowing an unauthenticated attacker on an adjacent network to achieve low confidentiality impact, primarily unauthorized information disclosure, with low attack complexity. Although not currently listed on the CISA KEV catalog for active exploitation, public exploit code is available, suggesting a potential for future exploitation, despite minimal community discussion and media coverage to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dnr-202l_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dnr-326_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dns-1100-4_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dns-120_firmware:*:*:*:*:*:*:*:* | ||
<= 2026-02-05CPE matchmatch criteria | cpe:2.3:o:dlink:dns-1200-05_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.