← Terug naar overzicht

A critical OS command injection vulnerability has been identified in D-Link DNS-327L and DNS-340L network-attached storage devices up to firmware version 20260717. The flaw resides in the /cgi-bin/ve_mgr.cgi file, where manipulation of the f_dev argument enables remote OS command injection. The vulnerability can be exploited remotely without physical access to the device. A public exploit has already been published and may be actively used by threat actors. The affected devices are consumer and small business NAS products from D-Link. The vulnerability has been catalogued in VulDB and NVD. Users of the affected devices should apply patches or mitigations as soon as they become available. The existence of a public exploit significantly raises the risk of exploitation in the wild.

Affected products

  • D-Link DNS-327L
  • D-Link DNS-340L

Related CVE's

  • CVE-2026-82690

IOC's

/cgi-bin/ve_mgr.cgi

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities