CVE-2026-4529

A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.
References
Link Resource
https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dhp1320-dlink Exploit Third Party Advisory
https://vuldb.com/?ctiid.352317 Third Party Advisory VDB Entry
https://vuldb.com/?id.352317 Third Party Advisory VDB Entry
https://vuldb.com/?submit.773932 Third Party Advisory VDB Entry
https://www.dlink.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dhp-1320_firmware:1.00wwb04:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dhp-1320:a1:*:*:*:*:*:*:*

History

30 Apr 2026, 16:33

Type Values Removed Values Added
CPE cpe:2.3:o:dlink:dhp-1320_firmware:1.00wwb04:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dhp-1320:a1:*:*:*:*:*:*:*
First Time Dlink dhp-1320
Dlink dhp-1320 Firmware
Dlink
Summary
  • (es) Se identificó una vulnerabilidad en D-Link DHP-1320 1.00WWB04. Esto afecta a la función redirect_count_down_page del componente Gestor SOAP. Dicha manipulación conduce a un desbordamiento de búfer basado en pila. El ataque puede ejecutarse de forma remota. El exploit está disponible públicamente y podría ser utilizado. Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el mantenedor.
References () https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dhp1320-dlink - () https://github.com/xiaobor123/vul-finds/tree/main/vul-find-dhp1320-dlink - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.352317 - () https://vuldb.com/?ctiid.352317 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.352317 - () https://vuldb.com/?id.352317 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.773932 - () https://vuldb.com/?submit.773932 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product

21 Mar 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 23:16

Updated : 2026-04-30 16:33


NVD link : CVE-2026-4529

Mitre link : CVE-2026-4529

CVE.ORG link : CVE-2026-4529


JSON object : View

Products Affected

dlink

  • dhp-1320
  • dhp-1320_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow