← Back to overview

A critical OS command injection vulnerability has been discovered in multiple D-Link NAS devices including DNS-320L, DNS-327L, DNS-340L, and DNS-345 up to firmware version 20260717. The vulnerability exists in the CGI Handler component, specifically in the /cgi-bin/usb_device.cgi file. Attackers can exploit the f_ups_ip argument to inject and execute arbitrary OS commands remotely. The attack can be performed remotely without physical access to the device. A public exploit has been disclosed, making active exploitation a significant risk. The vulnerability affects a wide range of D-Link NAS products commonly used in home and small business environments. Given the public availability of the exploit, unpatched devices are at immediate risk of compromise. Users are advised to apply patches or mitigations as soon as they become available from D-Link.

Affected products

  • D-Link DNS-320L
  • D-Link DNS-327L
  • D-Link DNS-340L
  • D-Link DNS-345

Related CVE's

  • CVE-2026-82691

IOC's

/cgi-bin/usb_device.cgi

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities