ZeroHour

CVE-2026-85223

moderate

Authenticated OS Command Injection in D-Link DNS-340L NAS Dropbox CGI Handler

CVSS 4.0
8.6 high
EPSS
2%p75
Published
()
Modified
AI analysis

CVE-2026-85223 is an OS command injection flaw (CWE-77/CWE-78) in the CGI handler of the D-Link DNS-340L network-attached storage (NAS) device, specifically in the script /cgi-bin/dropbox.cgi. A remote attacker with low-privileged (i.e., authenticated) access, as indicated by the PR:L component of the CVSS 4.0 vector, can manipulate the callback_url or sync_interval arguments of the Dropbox-related CGI endpoint to inject and execute operating-system commands on the device. Successful exploitation yields arbitrary command execution on the NAS, and the high-impact CVSS 4.0 scores for confidentiality, integrity, and availability indicate the attacker can effectively compromise the device, its stored data, and connected services such as the linked Dropbox account. Only the DNS-340L running firmware version 1.01B04 is named as affected in the available data, and no fixed version is documented yet. A working exploit has been made public, but the issue is not yet in CISA's KEV catalog and EPSS currently assigns a 1.6% probability of exploitation within 30 days (75th percentile), so no confirmed in-the-wild compromises are documented.

What to do: Owners should check whether their DNS-340L is running firmware 1.01B04 and install patched firmware from D-Link as soon as it is released (no fixed version is specified in the available data). Until then, do not expose the device's web administration interface directly to the internet, restrict access to trusted networks or a VPN, and consider disabling the Dropbox sync feature if the CGI endpoint cannot be isolated. Ensure default or weak credentials have been changed, since exploitation requires an authenticated account.

Affected
D-Link DNS-340L network-attached storage (NAS) device, /cgi-bin/dropbox.cgi CGI handlerfirmware 1.01B04 (no other versions confirmed in the available data)
Estimated exposure
moderatelikely on the order of tens of thousands of deployed units, with a smaller subset (roughly thousands) directly exposed to the internet — The DNS-340L is a consumer/SOHO 4-bay NAS with no published install-base figures, so this estimate is based on typical deployment patterns for D-Link ShareCenter-era devices, many of which are reachable from the internet via port…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.