ZeroHour

CVE-2026-85222

niche

Authenticated OS command injection in D-Link DNS-340L Add-On Center

CVSS 4.0
8.5 high
EPSS
2%p81
Published
()
Modified
AI analysis

CVE-2026-85222 is an operating-system command injection flaw in the Add-On Center component of the D-Link DNS-340L network-attached storage device, located in the /cgi-bin/addon_center.cgi handler. An attacker triggers it by submitting crafted values in the f_name, f_url, f_flag, and f_login_user parameters, which are passed to the underlying shell without proper validation, allowing arbitrary command execution on the NAS. The CVSS 4.0 vector indicates the attack is network-based but requires high-level privileges, meaning an attacker likely needs valid administrator credentials on the device; a successful attacker gains full confidentiality, integrity, and availability impact, effectively complete compromise of the NAS. Affected deployments are D-Link DNS-340L units, confirmed for firmware 1.01B04 (other firmware versions are unconfirmed in the available data). A public exploit is described as disclosed and potentially in use, but the flaw is not yet in CISA's KEV catalog and EPSS puts 30-day exploitation probability at roughly 2%.

What to do: Check the firmware version of any DNS-340L on your network and review D-Link's support pages for an updated firmware release, since no fixed version is confirmed in the available data. Restrict or remove WAN-facing access to the NAS admin interface, use strong unique administrator credentials (the flaw requires admin privileges), and disable the Add-On Center feature if it is not needed. Monitor the device for signs of the disclosed exploit being used, as EPSS indicates a non-trivial near-term exploitation probability.

Affected
D-Link DNS-340L (4-bay network storage / NAS)1.01B04 (firmware confirmed affected; other versions not specified in the available data)
Estimated exposure
nicheon the order of thousands to low tens of thousands of DNS-340L units deployed worldwide, with only a subset of those admin interfaces exposed to the internet — The DNS-340L is a single, older 4-bay consumer/SOHO NAS model with no published install-base figures, so the estimate reflects typical single-model legacy NAS deployment counts and internet-exposed D-Link NAS populations seen in public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.