ZeroHour

CVE-2026-82691

large

OS Command Injection in D-Link DNS-320L/327L/340L/345 NAS via usb_device.cgi

CVSS 4.0
8.5 high
EPSS
2%p81
Published
()
Modified
AI analysis

CVE-2026-82691 is an operating system command injection flaw (CWE-77/CWE-78) in the CGI handler of D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 network-attached storage devices, triggered through the f_ups_ip argument of /cgi-bin/usb_device.cgi. A remote attacker who can reach the device's web interface and, per the CVSS 4.0 scoring (PR:H), holds high-privilege (admin) credentials can send a crafted value in that argument to execute arbitrary operating system commands on the NAS. Successful exploitation yields high impact on confidentiality, integrity and availability of the device and potentially on subsequent systems, effectively giving the attacker control of the NAS. All four models running firmware up to and including the 20260717 (2026-07-17) build are affected. A public exploit exists and the flaw may be used, but it is not in CISA KEV and there is no confirmed widespread in-the-wild campaign yet; EPSS estimates a 2.1% (81st percentile) probability of exploitation in the next 30 days.

What to do: Check the firmware build on any DNS-320L, DNS-327L, DNS-340L or DNS-345 and, if it is dated 20260717 or earlier, monitor D-Link's support/download pages for updated firmware, as the advisory names no fixed release. Until a patch is available, keep the NAS web administration interface off the public internet (restrict to LAN/VPN with firewall rules) and ensure strong, unique admin credentials, since the CVSS scoring indicates the attack requires high-privilege access. Verify that any remote-access or UPnP-forwarded rules exposing the NAS web UI have been disabled or limited to trusted sources.

Affected
D-Link DNS-320Lall firmware up to and including the 20260717 build
D-Link DNS-327Lall firmware up to and including the 20260717 build
D-Link DNS-340Lall firmware up to and including the 20260717 build
D-Link DNS-345all firmware up to and including the 20260717 build
Estimated exposure
largeapprox. hundreds of thousands of deployed NAS units (installed-base estimate; the internet-exposed subset is likely far smaller, possibly tens of thousands) — No public scan counts or install statistics are available for these models, so the estimate extrapolates from the long sales history of D-Link's consumer/SOHO ShareCenter NAS line, in which these four models were staple offerings, while…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.