PT-2026-39536 · D Link · Dcs-935L

0Xcc12138

·

Published

2026-05-10

·

Updated

2026-05-11

·

CVE-2026-8260

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DCS-935L versions prior to 1.10.01
Description A buffer overflow can be triggered remotely via the HNAP Service. The issue exists in the SetDeviceSettings() function within the '/web/cgi-bin/hnap/hnap service' endpoint when manipulating the AdminPassword argument.
Recommendations Update to a version later than 1.10.01. As a temporary workaround, restrict access to the '/web/cgi-bin/hnap/hnap service' endpoint to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-8260

Affected Products

Dcs-935L