CVE-2026-12174: D-Link DCS-935L HTTP rhea snprintf format string
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the affected D-Link DCS-935L device (especially its web/management interface such as /web/cgi-bin/) to trusted IP addresses only, or otherwise isolate the device from untrusted networks until a vendor fix is available.
- Operational
Monitor D-Link advisories for a firmware update addressing the snprintf format-string vulnerability in DCS-935L 1.10.01 and apply the vendor-provided firmware update as soon as it is released. Until patched, consider removing the device from exposure to untrusted networks and inspect logs for signs of exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12174?
CVE-2026-12174 has a severity rating of high with a score of 8.8.
How do I fix CVE-2026-12174?
To fix CVE-2026-12174, it is recommended to update the D-Link DCS-935L firmware to the latest version provided by the vendor.
What components are affected by CVE-2026-12174?
CVE-2026-12174 affects the HTTP Handler component, specifically the function snprintf in the file /web/cgi-bin/greece/rhea.
Is CVE-2026-12174 exploitable remotely?
Yes, CVE-2026-12174 can be exploited remotely, making it critical to address.
What type of vulnerability is CVE-2026-12174?
CVE-2026-12174 is classified as a buffer overflow vulnerability.