← back
CVE-2026-12174

D-Link DCS-935L HTTP rhea snprintf format string

CVSS 8.7 HIGHEPSS 0.6%CWE-119CWE-134
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.7EPSS 0.6%KEV nãoPoC públicaPatch
Lifecycle
13 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DCS-935L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →