Junglewise Threat Intelligence

CVE-2026-5211: D-Link Multiple NAS Devices stack overflow in app_mgr.cgi

CVE-2026-5211 · Severity: high · CVSS 8.8 · Published 2026-03-31

Technologies: D-Link DNS-321, D-Link DNR-202L, D-Link DNS-315L, D-Link DNS-120, D-Link DNR-322L, D-Link DNS-320L, D-Link DNS-320LW. Vendors: D-Link.

Executive brief

A security vulnerability has been identified in several D-Link Network Attached Storage (NAS) and Video Recorder devices. These devices are commonly used by small businesses and home users to store files and manage security camera footage. An attacker could exploit this flaw to crash the device or potentially take full control of it, leading to data loss or unauthorized access to stored information.

Technical details

A stack-based buffer overflow vulnerability exists in the 'UPnP_AV_Server_Path_Del' function within the '/cgi-bin/app_mgr.cgi' binary of multiple D-Link NAS and DNR devices. The vulnerability is triggered by providing an excessively long string to the 'f_dir' parameter via a POST request. Because the input is copied to a local stack variable without proper bounds checking, an attacker can overwrite the return address to achieve arbitrary code execution or cause a persistent denial of service (system crash). While the attack vector is network-based, the provided PoC suggests that authentication (e.g., a valid session cookie) may be required. Public exploit code is available.

Affected products

  • D-Link DNS-120 up to 20260205
  • D-Link DNR-202L up to 20260205
  • D-Link DNS-315L up to 20260205
  • D-Link DNS-320 up to 20260205
  • D-Link DNS-320L up to 20260205
  • D-Link DNS-320LW up to 20260205
  • D-Link DNS-321 up to 20260205
  • D-Link DNR-322L up to 20260205
  • D-Link,versions: DNS-323

Timeline

  • 2026-03-31: disclosed: Initial disclosure date

References