A critical OS command injection vulnerability has been identified in D-Link DNS-340L firmware version 1.01B04. The vulnerability resides in the /cgi-bin/addon_center.cgi file within the Add-On Center component. Attackers can manipulate the arguments f_name, f_url, f_flag, and f_login_user to inject and execute arbitrary OS commands. The attack can be launched remotely without physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. This vulnerability poses a significant threat to network-attached storage devices running the affected firmware. No patch or mitigation details are currently provided in the advisory. Users of the affected device should monitor D-Link's official security advisories for updates.
/cgi-bin/addon_center.cgi