CVE-2026-4207
Severity CVSS v4.0:
MEDIUM
Type:
CWE-74
Injection
Publication date:
16/03/2026
Last modified:
16/03/2026
Description
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. This impacts the function cgi_device/cgi_sms_test/cgi_firmware_upload/cgi_ntp_time of the file /cgi-bin/system_mgr.cgi. Executing a manipulation can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
6.50
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_141/141.md
- https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_142/142.md
- https://vuldb.com/?ctiid_351119=
- https://vuldb.com/?id_351119=
- https://vuldb.com/?submit_770420=
- https://vuldb.com/?submit_770422=
- https://vuldb.com/?submit_770423=
- https://vuldb.com/?submit_770425=
- https://www.dlink.com/



