← Back to overview

A critical OS command injection vulnerability has been identified in D-Link DNS-340L firmware version 1.01B04. The vulnerability exists in the /cgi-bin/dropbox.cgi file within the CGI Handler component. An attacker can exploit this by manipulating the callback_url or sync_interval arguments to inject arbitrary OS commands. The attack can be initiated remotely without requiring physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-85223 and is tracked across multiple vulnerability databases including NVD and VulDB. D-Link NAS devices are commonly deployed in home and small business environments, making this a significant risk for a wide range of users. No patch information is explicitly mentioned in the article.

Affected products

  • D-Link DNS-340L 1.01B04

Related CVE's

  • CVE-2026-85223

Categories

  • Mobile & IoT
  • Network Infrastructure