Executive brief
A security vulnerability exists in several D-Link Network Attached Storage (NAS) and Video Recorder (NVR) devices. These devices are used to store and manage data or security camera footage on a network. An attacker can exploit this flaw to crash the device or potentially take full control of it, leading to data loss, service outages, or unauthorized access to stored files.
Technical details
A stack-based buffer overflow vulnerability exists in the cgi_adduser_to_session function within the /cgi-bin/account_mgr.cgi component of multiple D-Link NAS and NVR models. The vulnerability is triggered by providing excessively long strings to the read_list, write_list, or decline_list parameters during a POST request. Because the application fails to validate the length of these inputs before copying them to local stack variables, an attacker can overwrite the return address to redirect execution flow. While the attack requires network reachability and low-level authentication (PR:L), successful exploitation can lead to complete system compromise or persistent denial of service. A public exploit (PoC) has been disclosed.
Affected products
- D-Link DNS-120 up to 20260205
- D-Link DNR-202L up to 20260205
- D-Link DNS-315L up to 20260205
- D-Link DNS-320 up to 20260205
- D-Link DNS-320L up to 20260205
- D-Link DNS-320LW up to 20260205
- D-Link DNS-321 up to 20260205
- D-Link DNR-322L up to 20260205
- D-Link,versions: DNS-323
Timeline
- 2026-03-31: advisory: Initial disclosure of CVE-2026-5213