A critical OS command injection vulnerability has been identified in D-Link DNS-340L firmware version 1.01B04. The vulnerability exists in the /cgi-bin/dropbox.cgi file within the CGI Handler component. An attacker can exploit this by manipulating the callback_url or sync_interval arguments to inject arbitrary OS commands. The attack can be initiated remotely without requiring physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-85223 and is tracked across multiple vulnerability databases including NVD and VulDB. D-Link NAS devices are commonly deployed in home and small business environments, making this a significant risk for a wide range of users. No patch information is explicitly mentioned in the article.