CVE-2026-82688
moderateOS command injection in D-Link DNS-340L/DNS-345 NAS Virtual Volume handler
A command injection flaw (CWE-77/CWE-78) exists in the Virtual Volume handler of D-Link DNS-340L and DNS-345 NAS devices running firmware 1.01B04, 1.03B06, 1.04.B02, or 1.05b04. A remote attacker who has obtained administrator-level access to the device's web interface can inject operating-system commands through the f_sharename, f_target, or f_name parameters of /cgi-bin/virtual_vol.cgi, which are then executed on the device. Successful exploitation yields full compromise of the NAS, including reading, modifying, or destroying stored data and running arbitrary commands with the device's privileges. Any DNS-340L or DNS-345 deployment on the affected firmware is exposed, especially where the web interface is reachable from the internet, although the requirement for high privileges (reflected in the CVSS 4.0 score of 8.5) limits exploitation to attackers with admin credentials. An exploit has been publicly disclosed and may be used; the flaw is not yet in CISA KEV, and EPSS estimates a roughly 2.8% (86th percentile) probability of exploitation in the next 30 days, with no confirmed in-the-wild incidents recorded.
What to do: Inventory your environment for DNS-340L and DNS-345 units and compare firmware versions against the affected list (1.01B04, 1.03B06, 1.04.B02, 1.05b04), then apply the latest firmware D-Link publishes for these models (no fixed version is specified in the advisory). Until patched, keep the NAS administration interface off the internet or restrict it to VPN/trusted networks, since exploitation requires administrator-level credentials. Additionally, review access logs for requests to /cgi-bin/virtual_vol.cgi containing shell metacharacters in the f_sharename, f_target, or f_name parameters.
| D-Link DNS-340L | firmware 1.01B04, 1.03B06, 1.04.B02, 1.05b04 (version list is shared across both affected models; the advisory does not map versions to individual models) |
| D-Link DNS-345 | firmware 1.01B04, 1.03B06, 1.04.B02, 1.05b04 (version list is shared across both affected models; the advisory does not map versions to individual models) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.