A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used.
Metrics
Affected Vendors & Products
References
History
Mon, 11 May 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dcs-935l |
|
| Vendors & Products |
D-link
D-link dcs-935l |
Mon, 11 May 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of the file /web/cgi-bin/hnap/hnap_service of the component HNAP Service. The manipulation of the argument AdminPassword results in buffer overflow. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Title | D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow | |
| Weaknesses | CWE-119 CWE-120 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-11T01:15:09.977Z
Updated: 2026-05-11T01:15:09.977Z
Reserved: 2026-05-10T15:16:46.711Z
Link: CVE-2026-8260
No data.
Status : Undergoing Analysis
Published: 2026-05-11T02:16:27.583
Modified: 2026-05-11T15:06:08.253
Link: CVE-2026-8260
No data.
ReportizFlow