6.5

CVE-2026-16448

Exploit

D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerD-Link
Produkt DNS-120
Version 20260205
Status affected
HerstellerD-Link
Produkt DNR-202L
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-315L
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-320
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-320L
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-320LW
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-321
Version 20260205
Status affected
HerstellerD-Link
Produkt DNR-322L
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-323
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-325
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-326
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-327L
Version 20260205
Status affected
HerstellerD-Link
Produkt DNR-326
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-340L
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-343
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-345
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-726-4
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-1100-4
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-1200-05
Version 20260205
Status affected
HerstellerD-Link
Produkt DNS-1550-04
Version 20260205
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.06% 0.609
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@vuldb.com 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.dlink.com/
https://vuldb.com/vuln/380827
https://vuldb.com/vuln/380827/cti
https://vuldb.com/cve/CVE-2026-16448
https://vuldb.com/submit/858469
https://ucn9h68n9289.feishu.cn/docx/OfhNdwzvXoBlJBxDIW7clVmjnuh?from=from_copylink