ID

VAR-202606-0848


CVE

CVE-2026-12174


TITLE

D-Link Corporation of DCS-935L  Multiple vulnerabilities in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953

DESCRIPTION

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The exploit is publicly available and could be misused.- All information handled by the software may be leaked to external parties. - All information handled by the software may be overwritten. - The software may completely shut down

Trust: 1.62

sources: NVD: CVE-2026-12174 // JVNDB: JVNDB-2026-019953

AFFECTED PRODUCTS

vendor:dlinkmodel:dcs-935lscope:eqversion:1.10.01

Trust: 1.0

vendor:d linkmodel:dcs-935lscope: - version: -

Trust: 0.8

vendor:d linkmodel:dcs-935lscope:eqversion: -

Trust: 0.8

vendor:d linkmodel:dcs-935lscope:eqversion:dcs-935l firmware 1.10.01

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953 // NVD: CVE-2026-12174

CVSS

SEVERITY

CVSSV2

CVSSV3

cna@vuldb.com: CVE-2026-12174
value: HIGH

Trust: 1.0

OTHER: JVNDB-2026-019953
value: HIGH

Trust: 0.8

cna@vuldb.com: CVE-2026-12174
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

OTHER: JVNDB-2026-019953
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

cna@vuldb.com: CVE-2026-12174
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2026-019953
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953 // NVD: CVE-2026-12174

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.0

problemtype:CWE-134

Trust: 1.0

problemtype:Buffer error (CWE-119) [ others ]

Trust: 0.8

problemtype: Format string problem (CWE-134) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953 // NVD: CVE-2026-12174

PATCH

title://vuldb.com/vuln/370815url:https://github.com/Real-Simplicity/cve-database/tree/main/CVE_Report_DLink_DCS935L_Format_String

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953

EXTERNAL IDS

db:NVDid:CVE-2026-12174

Trust: 2.6

db:JVNDBid:JVNDB-2026-019953

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953 // NVD: CVE-2026-12174

REFERENCES

url:https://www.dlink.com/

Trust: 1.8

url:https://vuldb.com/cve/cve-2026-12174

Trust: 1.0

url:https://vuldb.com/submit/837209

Trust: 1.0

url:https://vuldb.com/vuln/370815

Trust: 1.0

url:https://vuldb.com/vuln/370815/cti

Trust: 1.0

url:https://github.com/real-simplicity/cve-database/tree/main/cve_report_dlink_dcs935l_format_string

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2026-12174

Trust: 0.8

sources: JVNDB: JVNDB-2026-019953 // NVD: CVE-2026-12174

SOURCES

db:JVNDBid:JVNDB-2026-019953
db:NVDid:CVE-2026-12174

LAST UPDATE DATE

2026-06-19T23:21:49.580000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2026-019953date:2026-06-17T06:35:00
db:NVDid:CVE-2026-12174date:2026-06-16T15:27:14.280

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2026-019953date:2026-06-17T00:00:00
db:NVDid:CVE-2026-12174date:2026-06-13T21:16:18.830