PT-2026-29614 · D Link · Dnr-202L+18

Ziyue Xie

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-5312

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function FMT restart/Status HDInfo/SMART List/ScanDisk info/ScanDisk/volume status/Get Volume Mapping/FMT check disk remount state/FMT rebuildinfo/FMT result list/FMT result list phy/FMT get dminfo/FMT manually rebuild info/Get current raidtype of the file /cgi-bin/dsk mgr.cgi. Executing a manipulation can lead to improper access controls. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.

Exploit

Fix

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2026-5312

Affected Products

Dnr-202L
Dnr-322L
Dnr-326
Dns-1100-4
Dns-120
Dns-1200-05
Dns-1550-04
Dns-315L
Dns-320
Dns-320L
Dns-321
Dns-323
Dns-325
Dns-326
Dns-327L
Dns-340L
Dns-343
Dns-345
Dns-726-4