Vulnerability Description
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dcs-935L Firmware | 1.10.01 |
| Dlink | Dcs-935L | - |
Related Weaknesses (CWE)
References
- https://github.com/Real-Simplicity/cve-database/tree/main/CVE_Report_DLink_DCS93Third Party Advisory
- https://vuldb.com/cve/CVE-2026-12174Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/837209Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/370815Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/370815/ctiPermissions RequiredVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2026-12174?
CVE-2026-12174 is a vulnerability with a CVSS score of 8.8 (HIGH). A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of...
How severe is CVE-2026-12174?
CVE-2026-12174 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12174?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dcs-935L Firmware, Dlink Dcs-935L.