


Perceptive Security
SOC/SIEM Consultancy

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 15:02:19
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A critical OS command injection vulnerability has been identified in D-Link DNS-327L and DNS-340L network-attached storage devices up to firmware version 20260717. The flaw resides in the /cgi-bin/ve_mgr.cgi file, where manipulation of the f_dev argument enables remote OS command injection. The vulnerability can be exploited remotely without physical access to the device. A public exploit has already been published and may be actively used by threat actors. The affected devices are consumer and small business NAS products from D-Link. The vulnerability has been catalogued in VulDB and NVD. Users of the affected devices should apply patches or mitigations as soon as they become available. The existence of a public exploit significantly raises the risk of exploitation in the wild.
Technical details
Mitigation steps:
Affected products:
D-Link DNS-327L
D-Link DNS-340L
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82690
https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-004-vulndb.md
https://vuldb.com/cve/CVE-2026-82690
https://vuldb.com/submit/894209
https://vuldb.com/vuln/397178
https://vuldb.com/vuln/397178/cti
https://www.dlink.com/
Related CVE's:
Related threat actors:
IOC's:
/cgi-bin/ve_mgr.cgi
This article was created with the assistance of AI technology by Perceptive.
