CVE-2026-85223
moderateAuthenticated OS Command Injection in D-Link DNS-340L NAS Dropbox CGI Handler
CVE-2026-85223 is an OS command injection flaw (CWE-77/CWE-78) in the CGI handler of the D-Link DNS-340L network-attached storage (NAS) device, specifically in the script /cgi-bin/dropbox.cgi. A remote attacker with low-privileged (i.e., authenticated) access, as indicated by the PR:L component of the CVSS 4.0 vector, can manipulate the callback_url or sync_interval arguments of the Dropbox-related CGI endpoint to inject and execute operating-system commands on the device. Successful exploitation yields arbitrary command execution on the NAS, and the high-impact CVSS 4.0 scores for confidentiality, integrity, and availability indicate the attacker can effectively compromise the device, its stored data, and connected services such as the linked Dropbox account. Only the DNS-340L running firmware version 1.01B04 is named as affected in the available data, and no fixed version is documented yet. A working exploit has been made public, but the issue is not yet in CISA's KEV catalog and EPSS currently assigns a 1.6% probability of exploitation within 30 days (75th percentile), so no confirmed in-the-wild compromises are documented.
What to do: Owners should check whether their DNS-340L is running firmware 1.01B04 and install patched firmware from D-Link as soon as it is released (no fixed version is specified in the available data). Until then, do not expose the device's web administration interface directly to the internet, restrict access to trusted networks or a VPN, and consider disabling the Dropbox sync feature if the CGI endpoint cannot be isolated. Ensure default or weak credentials have been changed, since exploitation requires an authenticated account.
| D-Link DNS-340L network-attached storage (NAS) device, /cgi-bin/dropbox.cgi CGI handler | firmware 1.01B04 (no other versions confirmed in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.