Executive brief
A security vulnerability exists in the D-Link DNS-320 network storage device. This flaw allows an unauthorized person to upload files to the device over the internet without permission. This could lead to the storage of malicious software on the device or a complete takeover of the system, potentially compromising any data stored on it.
Technical details
An unrestricted file upload vulnerability exists in the D-Link DNS-320 ShareCenter NAS running firmware version 1.0.2. The flaw is located within the '/photo_center/php/uploadify.php' script, which fails to properly validate or restrict the types of files being uploaded. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload a malicious script (such as a PHP shell). Once uploaded, the attacker can execute the script to gain unauthorized access, manipulate files, or achieve full remote code execution on the device. Public exploit code is reportedly available.
Affected products
- D-Link DNS-320 1.0.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory