OS Command Injection Vulnerability in D-Link DNS-320 from D-Link
CVE-2026-8273
5.1MEDIUM
What is CVE-2026-8273?
A vulnerability has been discovered in the D-Link DNS-320, specifically within the cgi_set_host, cgi_set_ntp, cgi_fan_control, and cgi_merge_user functions in the system_mgr.cgi file. This weakness allows for OS command injection, enabling attackers to execute arbitrary commands remotely. Attackers can leverage this flaw to compromise the device's integrity and security, leading to potential unauthorized access to sensitive data.
Affected Version(s)
DNS-320 2.06B01