OS Command Injection Vulnerability in D-Link ShareCenter NAS Devices
CVE-2026-82691
Key Information:
Badges
What is CVE-2026-82691?
A potential OS command injection vulnerability has been identified in the D-Link ShareCenter NAS devices, specifically in the CGI Handler component located at /cgi-bin/usb_device.cgi. Attackers may manipulate the f_ups_ip argument to execute arbitrary commands on the operating system from a remote location. This flaw impacts various models including DNS-320L, DNS-327L, DNS-340L, and DNS-345, and has been publicly disclosed, making it critical for affected users to address the issue immediately to safeguard their devices.
Affected Version(s)
DNS-320L 20260717
DNS-327L 20260717
DNS-340L 20260717
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved