← Terug naar overzicht

A critical OS command injection vulnerability has been identified in D-Link DNS-340L firmware version 1.01B04. The vulnerability resides in the /cgi-bin/addon_center.cgi file within the Add-On Center component. Attackers can manipulate the arguments f_name, f_url, f_flag, and f_login_user to inject and execute arbitrary OS commands. The attack can be launched remotely without physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. This vulnerability poses a significant threat to network-attached storage devices running the affected firmware. No patch or mitigation details are currently provided in the advisory. Users of the affected device should monitor D-Link's official security advisories for updates.

Affected products

  • D-Link DNS-340L 1.01B04

Related CVE's

  • CVE-2026-85222

IOC's

/cgi-bin/addon_center.cgi

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities