top of page
perceptive_background_267k.jpg

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the fi…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 23:17:02

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities

A critical OS command injection vulnerability has been discovered in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to firmware version 20260717. The vulnerability exists in the CGI Handler component, specifically in the /cgi-bin/usb_device.cgi file. Attackers can exploit the f_ups_ip argument to inject and execute arbitrary OS commands remotely. The attack can be performed remotely without physical access to the device. A public exploit has been disclosed, making active exploitation a significant risk. The vulnerability affects a wide range of D-Link NAS products commonly used in home and small business environments. Given the public availability of the exploit, unpatched devices are at immediate risk of compromise. Users are advised to apply patches or mitigations as soon as they become available from D-Link.

Technical details

Mitigation steps:

Affected products:

D-Link DNS-320L
D-Link DNS-327L
D-Link DNS-340L
D-Link DNS-345

Related links:

Related CVE's:

Related threat actors:

IOC's:

/cgi-bin/usb_device.cgi

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page