D Link · Dcs-935L · CVE-2026-12174
**Name of the Vulnerable Software and Affected Versions**
D-Link DCS-935L version 1.10.01
**Description**
A format string issue exists in the HTTP Handler component. The problem occurs within the `snprintf()` function located in the `/web/cgi-bin/greece/rhea` file. A remote attacker can trigger this by manipulating the `data` argument.
**Recommendations**
For version 1.10.01, apply the available patches provided by the manufacturer.
As a temporary mitigation, restrict access to the `/web/cgi-bin/greece/rhea` endpoint to minimize the risk of exploitation.