{"id": "CVE-2026-4194", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Secondary", "source": "cna@vuldb.com", "cvssData": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Secondary", "source": "cna@vuldb.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.3, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "LOW", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 3.4, "exploitabilityScore": 3.9}, {"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}], "cvssMetricV40": [{"type": "Secondary", "source": "cna@vuldb.com", "cvssData": {"Safety": "NOT_DEFINED", "version": "4.0", "Recovery": "NOT_DEFINED", "baseScore": 6.9, "Automatable": "NOT_DEFINED", "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "valueDensity": "NOT_DEFINED", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "exploitMaturity": "PROOF_OF_CONCEPT", "providerUrgency": "NOT_DEFINED", "userInteraction": "NONE", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "subIntegrityImpact": "NONE", "vulnIntegrityImpact": "LOW", "integrityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "subAvailabilityImpact": "NONE", "vulnAvailabilityImpact": "LOW", "availabilityRequirement": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "subConfidentialityImpact": "NONE", "vulnConfidentialityImpact": "LOW", "confidentialityRequirement": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED"}}]}, "published": "2026-03-16T14:20:03.150", "references": [{"url": "https://github.com/wudipjq/my_vuln/blob/main/D-Link8/vuln_96/96.md", "tags": ["Exploit", "Third Party Advisory"], "source": "cna@vuldb.com"}, {"url": "https://vuldb.com/?ctiid.351106", "tags": ["Permissions Required", "VDB Entry"], "source": "cna@vuldb.com"}, {"url": "https://vuldb.com/?id.351106", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cna@vuldb.com"}, {"url": "https://vuldb.com/?submit.769853", "tags": ["Third Party Advisory", "VDB Entry"], "source": "cna@vuldb.com"}, {"url": "https://www.dlink.com/", "tags": ["Product"], "source": "cna@vuldb.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "cna@vuldb.com", "description": [{"lang": "en", "value": "CWE-266"}, {"lang": "en", "value": "CWE-284"}]}], "descriptions": [{"lang": "en", "value": "A vulnerability was detected in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The impacted element is the function cgi_set_wto of the file /cgi-bin/system_mgr.cgi. Performing a manipulation results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used."}, {"lang": "es", "value": "Se detect\u00f3 una vulnerabilidad en D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 y DNS-1550-04 hasta el 20260205. El elemento afectado es la funci\u00f3n cgi_set_wto del archivo /cgi-bin/system_mgr.cgi. Realizar una manipulaci\u00f3n resulta en controles de acceso inadecuados. La explotaci\u00f3n remota del ataque es posible. El exploit es ahora p\u00fablico y puede ser utilizado."}], "lastModified": "2026-03-19T14:21:30.100", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dnr-202l_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E20A03F5-6985-4917-8E5B-48963FB62AF2", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dnr-202l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "07A92F2C-16FD-4A53-8066-83FEC2818DF5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dnr-326_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "926D7527-749C-4EDC-BF6A-76A199D5C1B5", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dnr-326:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "33CB308B-CF82-4E40-B2DC-23EBD48CD130"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-1100-4_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "84EB9230-7817-44C4-B248-BA9C1CEC2A41", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-1100-4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D5D08ED7-3E7F-4D30-890E-6535F6C34682"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-120_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F37C8F08-CEE9-4D2B-A273-B0AB57B874B5", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-120:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6E161E54-2FE9-4359-9B2D-8700D00DE8E7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-1200-05_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E85AC494-B63A-450E-BCDA-EC9C53A90A5A", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-1200-05:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D042C75D-6731-46B2-B11E-A009B9029B3F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-1550-04_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FAE008F5-7F73-4572-B575-FF0AD3FA2A78", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-1550-04:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E691E775-382C-4BA9-AA44-FBC3148D3E54"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-315l_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D1F595A-2595-4D20-A7F7-D0D954F72554", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-315l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "03C5CED7-55A7-4026-95CD-A2ADB5853823"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-320_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E07DE4E-1B8A-4B92-BBFB-7EAED86F04FB", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-320:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A0F5355E-F68D-49FE-9793-1FD9BD9AF3E1"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-320l_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CF83B802-8DD9-48D3-9DAC-C24774163FA4", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-320l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6C677E53-6885-4EC4-A7CC-E24E8F445F59"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-320lw_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F8FFDF4-6DDA-4FD8-A0E8-19C31187DBAD", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-320lw:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "45467ABC-BAA9-4EB0-9F97-92E31854CA8B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-321_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37D1BADB-2F38-40B0-A709-098C89249763", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-321:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2A278BC9-6197-43D9-93C2-3DF760856FB7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-322l_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "984FFAAE-E211-4CDA-9C5A-663DCA8867E7", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-322l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "82DD4836-A87C-42CC-A41B-B97B1BCA4886"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-323_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90990A02-23AC-4A71-9095-C703C2F718CE", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-323:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "94ED678A-AB4C-4637-B0D8-C232A0BB5D5F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-325_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3DCCD0CB-A8C6-455F-9888-A86BB933E68E", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-325:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8042169D-D9FA-4BD6-90D1-E0DE269E42B9"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-326_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B8293E4-993E-43E8-8FD0-F76DF42F1EA1", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-326:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D26F4F77-A6E3-4D7D-A781-BEB5FF7BC44F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-327l_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D4823E56-B773-4855-AAA1-204ECCB443F3", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-327l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DB305B29-7F89-4A52-9ECF-3DB0BDD2350D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-340l_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70B8EE5F-52E8-48CC-A08B-0F18976078B2", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-340l:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0646B20C-5642-4CEA-A96C-7E82AD94A281"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-343_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE10B057-CB8F-4DAA-8F4F-790EC3D828A9", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-343:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F968791D-D3BD-442C-818E-4E878B12776D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-345_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F90663BB-9C43-472F-9E79-91566C0DA82E", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-345:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C7E56821-7EA0-4CA1-BA17-7FD4ED9F794C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:dlink:dns-726-4_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9CBA8638-A030-43BC-A86F-09BA6F9189B8", "versionEndIncluding": "2026-02-05"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:dlink:dns-726-4:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "75E5010F-21BA-4B6B-B00C-2688268FD67B"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "cna@vuldb.com"}