A critical OS command injection vulnerability (CVE-2026-82692) has been discovered in D-Link DNS-340L and DNS-345 NAS devices up to firmware version 20260717. The vulnerability exists in the /cgi-bin/iscsi_mgr.cgi file, where manipulation of the alias, username, password, or volume_location arguments can lead to OS command injection. The attack can be initiated remotely without requiring physical access. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects iSCSI management functionality of the affected D-Link NAS devices. D-Link DNS-340L and DNS-345 are network-attached storage devices commonly used in home and small business environments. The public availability of the exploit significantly elevates the risk level for unpatched devices. Users of affected D-Link NAS devices should apply patches or mitigations immediately to prevent potential compromise.
/cgi-bin/iscsi_mgr.cgi