CVE-2026-85222
nicheAuthenticated OS command injection in D-Link DNS-340L Add-On Center
CVE-2026-85222 is an operating-system command injection flaw in the Add-On Center component of the D-Link DNS-340L network-attached storage device, located in the /cgi-bin/addon_center.cgi handler. An attacker triggers it by submitting crafted values in the f_name, f_url, f_flag, and f_login_user parameters, which are passed to the underlying shell without proper validation, allowing arbitrary command execution on the NAS. The CVSS 4.0 vector indicates the attack is network-based but requires high-level privileges, meaning an attacker likely needs valid administrator credentials on the device; a successful attacker gains full confidentiality, integrity, and availability impact, effectively complete compromise of the NAS. Affected deployments are D-Link DNS-340L units, confirmed for firmware 1.01B04 (other firmware versions are unconfirmed in the available data). A public exploit is described as disclosed and potentially in use, but the flaw is not yet in CISA's KEV catalog and EPSS puts 30-day exploitation probability at roughly 2%.
What to do: Check the firmware version of any DNS-340L on your network and review D-Link's support pages for an updated firmware release, since no fixed version is confirmed in the available data. Restrict or remove WAN-facing access to the NAS admin interface, use strong unique administrator credentials (the flaw requires admin privileges), and disable the Add-On Center feature if it is not needed. Monitor the device for signs of the disclosed exploit being used, as EPSS indicates a non-trivial near-term exploitation probability.
| D-Link DNS-340L (4-bay network storage / NAS) | 1.01B04 (firmware confirmed affected; other versions not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.