OS Command Injection Vulnerability in D-Link DNS-340L Add-On Center
CVE-2026-85222
Key Information:
Badges
What is CVE-2026-85222?
A vulnerability exists in the D-Link DNS-340L device, specifically within the Add-On Center component at the '/cgi-bin/addon_center.cgi' endpoint. This security flaw permits remote attackers to execute arbitrary OS commands by manipulating the f_name, f_url, f_flag, and f_login_user parameters. Given that the exploit has been publicly disclosed, it raises significant security concerns for users of this device. Those who manage or deploy the DNS-340L should take immediate steps to secure their systems and apply any available patches or updates.
Affected Version(s)
DNS-340L 1.01B04
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved