ZeroHour

CVE-2026-82688

moderate

OS command injection in D-Link DNS-340L/DNS-345 NAS Virtual Volume handler

CVSS 4.0
8.5 high
EPSS
3%p86
Published
()
Modified
AI analysis

A command injection flaw (CWE-77/CWE-78) exists in the Virtual Volume handler of D-Link DNS-340L and DNS-345 NAS devices running firmware 1.01B04, 1.03B06, 1.04.B02, or 1.05b04. A remote attacker who has obtained administrator-level access to the device's web interface can inject operating-system commands through the f_sharename, f_target, or f_name parameters of /cgi-bin/virtual_vol.cgi, which are then executed on the device. Successful exploitation yields full compromise of the NAS, including reading, modifying, or destroying stored data and running arbitrary commands with the device's privileges. Any DNS-340L or DNS-345 deployment on the affected firmware is exposed, especially where the web interface is reachable from the internet, although the requirement for high privileges (reflected in the CVSS 4.0 score of 8.5) limits exploitation to attackers with admin credentials. An exploit has been publicly disclosed and may be used; the flaw is not yet in CISA KEV, and EPSS estimates a roughly 2.8% (86th percentile) probability of exploitation in the next 30 days, with no confirmed in-the-wild incidents recorded.

What to do: Inventory your environment for DNS-340L and DNS-345 units and compare firmware versions against the affected list (1.01B04, 1.03B06, 1.04.B02, 1.05b04), then apply the latest firmware D-Link publishes for these models (no fixed version is specified in the advisory). Until patched, keep the NAS administration interface off the internet or restrict it to VPN/trusted networks, since exploitation requires administrator-level credentials. Additionally, review access logs for requests to /cgi-bin/virtual_vol.cgi containing shell metacharacters in the f_sharename, f_target, or f_name parameters.

Affected
D-Link DNS-340Lfirmware 1.01B04, 1.03B06, 1.04.B02, 1.05b04 (version list is shared across both affected models; the advisory does not map versions to individual models)
D-Link DNS-345firmware 1.01B04, 1.03B06, 1.04.B02, 1.05b04 (version list is shared across both affected models; the advisory does not map versions to individual models)
Estimated exposure
moderate≈1,000–10,000 deployed devices (legacy consumer NAS models; internet-exposed units likely in the low thousands) — DNS-340L/DNS-345 are older consumer/SOHO NAS models in D-Link's relatively small NAS line, so the plausible installed base is low tens of thousands and only a fraction of those devices have their web interface exposed to the internet,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.