Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Simplicity

#15922of 56,326
18Total CVSS
Vulnerabilities · 2
High
2
PT-2026-49083
9.0
2026-06-13
D Link · Dcs-935L · CVE-2026-12174
**Name of the Vulnerable Software and Affected Versions** D-Link DCS-935L version 1.10.01 **Description** A format string issue exists in the HTTP Handler component within the file '/web/cgi-bin/greece/rhea'. The problem occurs in the `snprintf()` function when the `data` argument is manipulated, allowing a remote attack to be launched. **Recommendations** For version 1.10.01, apply available patches. As a temporary workaround, restrict access to the '/web/cgi-bin/greece/rhea' endpoint to minimize the risk of exploitation.
PT-2026-53222
9.0
2026-05-29
D Link · Dcs-935L · CVE-2026-13545
**Name of the Vulnerable Software and Affected Versions** D-Link DCS-935L version 1.10.01 **Description** An OS command injection issue exists in the POST Parameter Handler component within the `setconf.cgi` file. The vulnerability occurs in the `sub 400E40()` function due to the failure to neutralize special elements when processing the `UID` parameter. A remote attacker can manipulate this parameter to execute arbitrary commands on the device with root-equivalent privileges. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the `setconf.cgi` endpoint to minimize the risk of exploitation.