Buffer Overflow Vulnerability in D-Link DCS-935L HNAP Service
CVE-2026-8260
Key Information:
Badges
What is CVE-2026-8260?
A buffer overflow vulnerability affects the D-Link DCS-935L camera models running firmware versions up to 1.10.01. The flaw exists in the SetDeviceSettings function of the HNAP Service, located at /web/cgi-bin/hnap/hnap_service. This vulnerability enables an attacker to manipulate the AdminPassword argument, potentially leading to remote code execution. An exploit has been publicly disclosed, posing significant risks for users of the affected devices.
Affected Version(s)
DCS-935L 1.10.01
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved