← Terug naar overzicht

A critical OS command injection vulnerability has been identified in D-Link DNS-340L and DNS-345 network-attached storage devices across multiple firmware versions (1.01B04, 1.03B06, 1.04.B02, 1.05b04). The vulnerability exists in the /cgi-bin/virtual_vol.cgi file within the Virtual Volume Handler component. Attackers can exploit this by manipulating the f_sharename, f_target, or f_name arguments to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation in the wild. This affects a widely deployed line of consumer and small business NAS devices manufactured by D-Link. The public disclosure and remote exploitability make this a high-severity issue requiring immediate attention and patching.

Affected products

  • D-Link DNS-340L
  • D-Link DNS-345

Related CVE's

  • CVE-2026-82688

Categories

  • Database & Storage
  • Mobile & IoT
  • Network Infrastructure