← Back to overview

A critical OS command injection vulnerability (CVE-2026-82689) has been identified in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to firmware version 20260717. The vulnerability exists in the /cgi-bin/isomount_mgr.cgi file within the ISO Image Handler component. Attackers can exploit the vulnerability by manipulating the upIsoRootPath argument to inject arbitrary OS commands. The attack can be carried out remotely without requiring physical access to the device. A public exploit is already available, significantly raising the risk of active exploitation. D-Link NAS devices are commonly used in home and small business environments, making this a widespread risk. The exposure of this vulnerability with a public proof-of-concept increases the urgency for patching or mitigation measures.

Affected products

  • D-Link DNS-320L
  • D-Link DNS-327L
  • D-Link DNS-340L
  • D-Link DNS-345

Related CVE's

  • CVE-2026-82689

IOC's

/cgi-bin/isomount_mgr.cgi

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities