CVE-2026-82689
largeAuthenticated OS Command Injection in D-Link DNS-320L/327L/340L/345 NAS
An OS command injection vulnerability (CWE-77/CWE-78) exists in the ISO Image Handler component of D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 network-attached storage devices running firmware up to and including the 20260717 build. A remote attacker sends a crafted value in the upIsoRootPath argument to /cgi-bin/isomount_mgr.cgi, which the device fails to sanitize before passing to the operating system; per the CVSS 4.0 vector (PR:L), the attacker must first hold low-privileged, i.e. authenticated, access to the device. Successful exploitation grants arbitrary command execution with high impact to confidentiality, integrity, and availability on the NAS and potentially subsequent systems it can reach, effectively a full device compromise. Anyone running affected firmware on these four consumer/SOHO NAS models is exposed, with risk concentrated on units whose web management interface is reachable from the internet. The source description reports the exploit is public and may be used; there is no CISA KEV listing yet, no public PoC is cataloged in the structured data, and EPSS assigns a 2.4% probability of exploitation within 30 days (83rd percentile).
What to do: Check D-Link's support site for updated firmware for the DNS-320L/327L/340L/345 and install any release newer than the 20260717 build once published. Until then, do not expose the NAS web administration interface directly to the internet (restrict via firewall or VPN), rotate NAS credentials since authentication is required for exploitation, and review device logs for suspicious requests to /cgi-bin/isomount_mgr.cgi containing unusual characters in the upIsoRootPath parameter. If the ISO mounting feature is unused, disable it as a mitigation.
| D-Link DNS-320L | Up to and including 20260717 (latest affected firmware build) |
| D-Link DNS-327L | Up to and including 20260717 (latest affected firmware build) |
| D-Link DNS-340L | Up to and including 20260717 (latest affected firmware build) |
| D-Link DNS-345 | Up to and including 20260717 (latest affected firmware build) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.