


Perceptive Security
SOC/SIEM Consultancy

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the fi…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 23:17:02
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A critical OS command injection vulnerability has been discovered in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to firmware version 20260717. The vulnerability exists in the CGI Handler component, specifically in the /cgi-bin/usb_device.cgi file. Attackers can exploit the f_ups_ip argument to inject and execute arbitrary OS commands remotely. The attack can be performed remotely without physical access to the device. A public exploit has been disclosed, making active exploitation a significant risk. The vulnerability affects a wide range of D-Link NAS products commonly used in home and small business environments. Given the public availability of the exploit, unpatched devices are at immediate risk of compromise. Users are advised to apply patches or mitigations as soon as they become available from D-Link.
Technical details
Mitigation steps:
Affected products:
D-Link DNS-320L
D-Link DNS-327L
D-Link DNS-340L
D-Link DNS-345
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82691
https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-005-vulndb.md
https://vuldb.com/cve/CVE-2026-82691
https://vuldb.com/submit/894210
https://vuldb.com/vuln/397179
https://vuldb.com/vuln/397179/cti
https://www.dlink.com/
Related CVE's:
Related threat actors:
IOC's:
/cgi-bin/usb_device.cgi
This article was created with the assistance of AI technology by Perceptive.
