A critical OS command injection vulnerability (CVE-2026-82691) has been identified in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 running firmware up to version 20260717. The vulnerability exists in the CGI Handler component, specifically in the /cgi-bin/usb_device.cgi file. By manipulating the f_ups_ip argument, a remote attacker can execute arbitrary OS commands on the affected device. The attack can be performed remotely without requiring physical access. A public exploit has already been disclosed, increasing the risk of active exploitation. D-Link NAS devices are commonly deployed in small business and home office environments, making this a significant threat to a wide range of users.
/cgi-bin/usb_device.cgi