CVE-2026-82692
largeOS Command Injection in D-Link DNS-340L/DNS-345 NAS iSCSI Manager CGI
CVE-2026-82692 is an OS command injection flaw (CWE-77/CWE-78) in the iSCSI management script /cgi-bin/iscsi_mgr.cgi on D-Link DNS-340L and DNS-345 network-attached storage devices running firmware up to 20260717. A remote attacker who holds valid (low-privilege) credentials can trigger it by submitting crafted values in the alias, username, password, or volume_location parameters, which are passed to the underlying operating system without proper sanitization. Successful injection results in arbitrary command execution on the NAS — reflected in the CVSS 4.0 base of 8.6 (High) with high impact on confidentiality, integrity, and availability — effectively giving the attacker control of the device and the data it stores and serves. Only D-Link DNS-340L and DNS-345 units with firmware dated on or before 2026-07-17 are named in the advisory; other D-Link NAS models are not listed as affected. The advisory notes the exploit has been made public and could be used, but no in-the-wild exploitation is confirmed, the flaw is not in CISA KEV, and EPSS assigns a 2.4% (83rd percentile) probability of exploitation within the next 30 days.
What to do: Inventory your environment for DNS-340L and DNS-345 units and check each device's firmware version; apply any D-Link firmware released after 2026-07-17 as soon as it is available, since the advisory does not name a specific fixed build. Until patched, do not expose the NAS web management interface to the internet (remove port forwards, restrict to trusted management networks or VPN), limit iSCSI Manager access to low-risk credentials, and review logs for suspicious or unexpected requests to /cgi-bin/iscsi_mgr.cgi.
| D-Link DNS-340L | firmware up to 20260717 (i.e., builds dated on or before 2026-07-17) |
| D-Link DNS-345 | firmware up to 20260717 (i.e., builds dated on or before 2026-07-17) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.