Junglewise Threat Intelligence

CVE-2026-5212: D-Link NAS and NVR stack overflow in webdav_mgr.cgi

CVE-2026-5212 · Severity: high · CVSS 8.8 · Published 2026-03-31

Technologies: D-Link DNS-321, D-Link,versions: DNR-322L, D-Link DNR-202L, D-Link DNS-315L, D-Link DNS-120, D-Link DNS-320L, D-Link DNS-320LW. Vendors: D-Link.

Executive brief

A security vulnerability has been identified in several D-Link Network Attached Storage (NAS) and Video Recorder (NVR) devices. These devices are commonly used by small businesses and home users to store files and manage security camera footage. An attacker could exploit this flaw to crash the device or potentially take full control of it, leading to data loss or unauthorized access to stored information.

Technical details

A stack-based buffer overflow vulnerability exists in the 'Webdav_Upload_File' function within the '/cgi-bin/webdav_mgr.cgi' binary of multiple D-Link NAS and NVR models. The vulnerability is triggered by providing an excessively long string to the 'f_file' (filename) argument during a file upload request. Because the application fails to validate the length of this input before copying it to a local stack variable, an attacker can overwrite the function's return address. This can be exploited remotely by an authenticated user to achieve arbitrary code execution or cause a persistent denial of service (system crash). Public exploit code (PoC) has been disclosed.

Affected products

  • D-Link DNS-120 up to 20260205
  • D-Link DNR-202L up to 20260205
  • D-Link DNS-315L up to 20260205
  • D-Link DNS-320 up to 20260205
  • D-Link DNS-320L up to 20260205
  • D-Link DNS-320LW up to 20260205
  • D-Link DNS-321 up to 20260205
  • D-Link,versions: DNR-322L

Timeline

  • 2026-03-31: disclosed: Vulnerability published on NVD

References