ZeroHour

CVE-2026-85224

large

Remote OS Command Injection in D-Link DNS-320 ShareCenter File Sharing

CVSS 4.0
8.5 high
EPSS
2%p81
Published
()
Modified
AI analysis

CVE-2026-85224 is an OS command injection flaw in the File Sharing component of the D-Link DNS-320 ShareCenter network-attached storage device, affecting firmware version 2.06B01. The flaw resides in the /cgi/file_sharing.cgi script, where manipulation of the fileurl argument allows attacker-supplied input to be executed as operating-system commands; the attack can be launched remotely, and the CVSS 4.0 vector's high privileges requirement (PR:H) indicates the attacker needs privileged access to the device, most likely an authenticated administrative session. Successful exploitation yields arbitrary command execution on the NAS with high impact to confidentiality, integrity, and availability, effectively enabling full compromise of the device and the data stored on it. Only owners of the D-Link DNS-320 ShareCenter, a legacy consumer NAS, are implicated by the advisory; no other D-Link products are named. The exploit has been publicly disclosed and may be used, but the flaw is not yet in CISA's KEV catalog and EPSS currently estimates only about a 2.2% probability of exploitation within the next 30 days.

What to do: Check D-Link's support site for an updated DNS-320 firmware addressing CVE-2026-85224; note the product is end-of-life, so a patch may be limited or unavailable, in which case stop exposing the device's web interface to the internet. As an interim mitigation, restrict or block inbound access to /cgi/file_sharing.cgi and review logs for requests carrying command-like content in the fileurl parameter.

Affected
D-Link DNS-320 ShareCenter2.06B01 (version named in the advisory; other firmware versions are not confirmed in the data)
Estimated exposure
largeon the order of tens of thousands of internet-exposed units (installed base of the legacy DNS-320 is larger, but many units are retired or not internet-facing) — Public internet scans (e.g., Shodan/Censys) have historically shown tens of thousands of D-Link ShareCenter NAS web interfaces exposed online, and the DNS-320's long production run and common practice of exposing NAS web UIs for remote…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.