Executive brief
A vulnerability exists in the D-Link DNS-320 storage device that allows unauthorized users to upload files to the system. This device is typically used for network-attached storage (NAS) to manage and share data within a home or small office. An attacker could exploit this to place malicious files on the device, potentially leading to a full system compromise, data loss, or unauthorized access to stored information.
Technical details
An unrestricted file upload vulnerability exists in the D-Link DNS-320 NAS device running firmware version 1.0.2. The flaw is located in the '/web/web_file/upload.php' script, which fails to properly validate or restrict the 'File' argument during processing. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to the web server. This can lead to remote code execution (RCE) if the attacker uploads a malicious script (such as a PHP shell) and executes it. The exploit for this vulnerability has been publicly disclosed.
Affected products
- D-Link DNS-320 1.0.2
Timeline
- 2026-07-21: advisory: NVD publication date
- 2026-07-21: disclosed: Public disclosure of the exploit