CVE-2026-8260
גבוהה 8.8
תיאור (מקור, אנגלית)
A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
7.4 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-2/8/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
dlink: dcs-935l firmware; dlink: dcs-935l
קישורים
- https://github.com/0xcc12138/DCS-935L-HNAP-Service-CVE ExploitThird Party Advisory
- https://vuldb.com/submit/809888 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362557 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/362557/cti Permissions RequiredVDB Entry
- https://www.dlink.com/ Product