CVE-2026-82690
moderateOS Command Injection in D-Link DNS-327L/DNS-340L NAS via ve_mgr.cgi
An OS command injection vulnerability (CWE-77/CWE-78) exists in the web management interface (/cgi-bin/ve_mgr.cgi) of D-Link DNS-327L and DNS-340L network-attached storage devices running firmware up to and including the 20260717 build. An attacker triggers it by sending crafted input in the f_dev argument of the ve_mgr.cgi script, causing arbitrary operating-system commands to execute on the device. Successful exploitation yields remote command execution on the NAS, exposing stored data and device control; the CVSS 4.0 vector (AV:N/AC:L/PR:H/UI:N with high impact on confidentiality, integrity and availability) indicates a network-based, low-complexity attack with no user interaction that requires high-privileged (admin-level) access. Owners and administrators of DNS-327L and DNS-340L units on affected firmware are impacted, especially where the management web interface is reachable from untrusted networks. A public exploit has been published, but the flaw is not yet in CISA KEV and EPSS estimates only a ~2.1% probability of exploitation in the next 30 days, so no widespread in-the-wild exploitation is confirmed.
What to do: Upgrade DNS-327L and DNS-340L firmware to a build newer than 20260717 as soon as D-Link publishes a fix (no fixed version is specified in the available data). Until then, restrict the NAS web interface to trusted networks and do not expose it directly to the internet, and check device/admin logs for unexpected requests to /cgi-bin/ve_mgr.cgi and signs of unauthorized admin activity.
| D-Link DNS-327L | through 20260717 (firmware up to and including the 20260717 build) |
| D-Link DNS-340L | through 20260717 (firmware up to and including the 20260717 build) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.