ZeroHour

CVE-2026-82692

large

OS Command Injection in D-Link DNS-340L/DNS-345 NAS iSCSI Manager CGI

CVSS 4.0
8.6 high
EPSS
2%p83
Published
()
Modified
AI analysis

CVE-2026-82692 is an OS command injection flaw (CWE-77/CWE-78) in the iSCSI management script /cgi-bin/iscsi_mgr.cgi on D-Link DNS-340L and DNS-345 network-attached storage devices running firmware up to 20260717. A remote attacker who holds valid (low-privilege) credentials can trigger it by submitting crafted values in the alias, username, password, or volume_location parameters, which are passed to the underlying operating system without proper sanitization. Successful injection results in arbitrary command execution on the NAS — reflected in the CVSS 4.0 base of 8.6 (High) with high impact on confidentiality, integrity, and availability — effectively giving the attacker control of the device and the data it stores and serves. Only D-Link DNS-340L and DNS-345 units with firmware dated on or before 2026-07-17 are named in the advisory; other D-Link NAS models are not listed as affected. The advisory notes the exploit has been made public and could be used, but no in-the-wild exploitation is confirmed, the flaw is not in CISA KEV, and EPSS assigns a 2.4% (83rd percentile) probability of exploitation within the next 30 days.

What to do: Inventory your environment for DNS-340L and DNS-345 units and check each device's firmware version; apply any D-Link firmware released after 2026-07-17 as soon as it is available, since the advisory does not name a specific fixed build. Until patched, do not expose the NAS web management interface to the internet (remove port forwards, restrict to trusted management networks or VPN), limit iSCSI Manager access to low-risk credentials, and review logs for suspicious or unexpected requests to /cgi-bin/iscsi_mgr.cgi.

Affected
D-Link DNS-340Lfirmware up to 20260717 (i.e., builds dated on or before 2026-07-17)
D-Link DNS-345firmware up to 20260717 (i.e., builds dated on or before 2026-07-17)
Estimated exposure
largelikely tens of thousands of deployed DNS-340L/DNS-345 NAS units worldwide, of which only a fraction (plausibly thousands) have the web management interface… — These are decade-old consumer/SOHO NAS models from a major vendor, suggesting a lifetime installed base in the tens of thousands based on typical legacy D-Link NAS sales and deployment patterns, while direct remote risk is limited to units…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.