ZeroHour

CVE-2026-82690

moderate

OS Command Injection in D-Link DNS-327L/DNS-340L NAS via ve_mgr.cgi

CVSS 4.0
8.5 high
EPSS
2%p81
Published
()
Modified
AI analysis

An OS command injection vulnerability (CWE-77/CWE-78) exists in the web management interface (/cgi-bin/ve_mgr.cgi) of D-Link DNS-327L and DNS-340L network-attached storage devices running firmware up to and including the 20260717 build. An attacker triggers it by sending crafted input in the f_dev argument of the ve_mgr.cgi script, causing arbitrary operating-system commands to execute on the device. Successful exploitation yields remote command execution on the NAS, exposing stored data and device control; the CVSS 4.0 vector (AV:N/AC:L/PR:H/UI:N with high impact on confidentiality, integrity and availability) indicates a network-based, low-complexity attack with no user interaction that requires high-privileged (admin-level) access. Owners and administrators of DNS-327L and DNS-340L units on affected firmware are impacted, especially where the management web interface is reachable from untrusted networks. A public exploit has been published, but the flaw is not yet in CISA KEV and EPSS estimates only a ~2.1% probability of exploitation in the next 30 days, so no widespread in-the-wild exploitation is confirmed.

What to do: Upgrade DNS-327L and DNS-340L firmware to a build newer than 20260717 as soon as D-Link publishes a fix (no fixed version is specified in the available data). Until then, restrict the NAS web interface to trusted networks and do not expose it directly to the internet, and check device/admin logs for unexpected requests to /cgi-bin/ve_mgr.cgi and signs of unauthorized admin activity.

Affected
D-Link DNS-327Lthrough 20260717 (firmware up to and including the 20260717 build)
D-Link DNS-340Lthrough 20260717 (firmware up to and including the 20260717 build)
Estimated exposure
moderatelikely tens of thousands of deployed legacy units worldwide, of which only a few thousand are plausibly internet-exposed (estimate) — Based on the legacy consumer/SOHO positioning of this D-Link ShareCenter NAS line and typical public internet-scan visibility for its web interface, since no authoritative install-base figure is provided in the data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.