← Terug naar overzicht

A critical OS command injection vulnerability has been identified in D-Link DNS-320 ShareCenter version 2.06B01. The flaw exists in the /cgi/file_sharing.cgi component, specifically through manipulation of the 'fileurl' argument in the File Sharing feature. Successful exploitation allows remote attackers to execute arbitrary OS commands on the affected device. The attack can be launched remotely without physical access to the device. A public exploit has been disclosed, significantly increasing the risk of active exploitation. The vulnerability affects network-attached storage devices commonly used in home and small business environments. D-Link has been referenced as the vendor responsible for the affected product. The public disclosure of the exploit raises the urgency for patching or mitigation. Users of the affected firmware version are advised to apply security updates or workarounds immediately.

Affected products

  • D-Link DNS-320 ShareCenter 2.06B01

Related CVE's

  • CVE-2026-85224

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities