A critical OS command injection vulnerability has been identified in D-Link DNS-340L and DNS-345 network-attached storage devices across multiple firmware versions (1.01B04, 1.03B06, 1.04.B02, 1.05b04). The vulnerability exists in the /cgi-bin/virtual_vol.cgi file within the Virtual Volume Handler component. Attackers can manipulate the arguments f_sharename, f_target, or f_name to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. D-Link NAS devices are commonly used in home and small business environments, broadening the potential attack surface. The vulnerability has been assigned CVE-2026-82688 and is tracked on NVD and VulnDB.