← Terug naar overzicht

A critical OS command injection vulnerability has been identified in multiple D-Link NAS devices, including the DNS-320L, DNS-327L, DNS-340L, and DNS-345 models up to firmware version 20260717. The vulnerability resides in the /cgi-bin/isomount_mgr.cgi file within the ISO Image Handler component. By manipulating the 'upIsoRootPath' argument, an attacker can inject arbitrary OS commands. The attack is remotely exploitable without requiring physical access to the device. A public exploit is already available, significantly increasing the risk of active exploitation in the wild. D-Link NAS devices are commonly used in home and small business environments, making this a widespread risk. Users are advised to apply patches or mitigations as soon as they become available from D-Link.

Affected products

  • D-Link DNS-320L
  • D-Link DNS-327L
  • D-Link DNS-340L
  • D-Link DNS-345

Related CVE's

  • CVE-2026-82689

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities