A critical OS command injection vulnerability has been identified in D-Link DNS-327L and DNS-340L NAS devices up to firmware version 20260717. The vulnerability exists in the /cgi-bin/ve_mgr.cgi file, where manipulation of the 'f_dev' argument allows an attacker to inject arbitrary OS commands. The flaw can be exploited remotely without requiring physical access to the device. A public exploit has already been published, increasing the risk of active exploitation. The vulnerability affects network-attached storage devices commonly used in home and small business environments. No official patch details are mentioned in the article. The issue has been documented in VulDB and referenced in NVD. Given the remote exploitability and public exploit availability, this is considered a high-severity issue. Users of affected D-Link NAS devices should monitor for vendor advisories and apply mitigations promptly.
/cgi-bin/ve_mgr.cgi