A critical OS command injection vulnerability has been identified in D-Link DNS-340L and DNS-345 network-attached storage devices across multiple firmware versions (1.01B04, 1.03B06, 1.04.B02, 1.05b04). The vulnerability exists in the /cgi-bin/virtual_vol.cgi file within the Virtual Volume Handler component. Attackers can exploit this by manipulating the f_sharename, f_target, or f_name arguments to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. This affects a widely deployed line of consumer and small business NAS devices manufactured by D-Link. The public disclosure and remote exploitability make this a high-severity issue requiring immediate attention and patching.