Junglewise Threat Intelligence

CVE-2026-16327: D-Link DNS-320 unrestricted file upload in upload.php

CVE-2026-16327 · Severity: high · CVSS 7.3 · Published 2026-07-21

Vendors: D-Link.

Executive brief

A vulnerability exists in the D-Link DNS-320 storage device that allows unauthorized users to upload files to the system. This device is typically used for network-attached storage (NAS) to manage and share data within a home or small office. An attacker could exploit this to place malicious files on the device, potentially leading to a full system compromise, data loss, or unauthorized access to stored information.

Technical details

An unrestricted file upload vulnerability exists in the D-Link DNS-320 NAS device running firmware version 1.0.2. The flaw is located in the '/web/web_file/upload.php' script, which fails to properly validate or restrict the 'File' argument during processing. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to the web server. This can lead to remote code execution (RCE) if the attacker uploads a malicious script (such as a PHP shell) and executes it. The exploit for this vulnerability has been publicly disclosed.

Affected products

  • D-Link DNS-320 1.0.2

Timeline

  • 2026-07-21: advisory: NVD publication date
  • 2026-07-21: disclosed: Public disclosure of the exploit

References