← Back to overview

A critical OS command injection vulnerability (CVE-2026-82692) was discovered in D-Link DNS-340L and DNS-345 NAS devices up to firmware version 20260717. The vulnerability exists in the /cgi-bin/iscsi_mgr.cgi file, where manipulation of the alias, username, password, or volume_location arguments can lead to OS command injection. The attack can be initiated remotely without physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects network-attached storage devices commonly used in home and small business environments. No patch information is currently indicated in the advisory. The public disclosure of the exploit makes this a high-priority issue for D-Link DNS-340L and DNS-345 users.

Affected products

  • D-Link DNS-340L
  • D-Link DNS-345

Related CVE's

  • CVE-2026-82692

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities