Junglewise Threat Intelligence

CVE-2026-16330: D-Link DNS-320 unrestricted file upload in uploadify.php

CVE-2026-16330 · Severity: high · CVSS 7.3 · Published 2026-07-21

Vendors: D-Link.

Executive brief

A security vulnerability exists in the D-Link DNS-320 storage device, a network-attached storage (NAS) system used for data backup and file sharing. An attacker can remotely upload unauthorized files to the device without needing a password. This could allow a malicious actor to compromise the device, potentially leading to data theft, service disruption, or a foothold for further attacks on the local network.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the D-Link DNS-320 NAS device running firmware version 1.0.2. The flaw is located in the '/web/jquery/uploader/uploadify.php' file, where improper access control and validation allow for the manipulation of arguments to facilitate unauthorized file uploads. This is a remote, unauthenticated attack vector that requires no user interaction. Successful exploitation allows an attacker to upload and potentially execute arbitrary files on the system. While a public exploit is reported to be available, no official patch for this legacy device is mentioned in the advisory.

Affected products

  • D-Link DNS-320 1.0.2

Timeline

  • 2026-07-21: disclosed: Initial publication date
  • 2026-07-21: advisory

References