OS Command Injection Vulnerability in D-Link DNS-320 from D-Link
CVE-2026-8273

5.1MEDIUM

Key Information:

Vendor

D-link

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-8273?

A vulnerability has been discovered in the D-Link DNS-320, specifically within the cgi_set_host, cgi_set_ntp, cgi_fan_control, and cgi_merge_user functions in the system_mgr.cgi file. This weakness allows for OS command injection, enabling attackers to execute arbitrary commands remotely. Attackers can leverage this flaw to compromise the device's integrity and security, leading to potential unauthorized access to sensitive data.

Affected Version(s)

DNS-320 2.06B01

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ST4R (VulDB User)
.