Executive brief
A security vulnerability has been identified in the D-Link DNS-320 network storage device. This flaw allows an unauthorized person to upload files to the device remotely without proper restrictions. An attacker could use this to compromise the device, potentially leading to data theft, service disruption, or unauthorized access to the local network.
Technical details
An unrestricted file upload vulnerability exists in the D-Link DNS-320 NAS device running firmware version 1.0.2. The flaw is located in the /web/function/save_ajax.php file due to improper validation of the 'Malicious Handler' argument. A remote, unauthenticated attacker can exploit this vulnerability to upload arbitrary files to the system. This can lead to remote code execution if the attacker is able to upload and subsequently execute a web shell or other malicious script. Public exploit code has been disclosed.
Affected products
- D-Link DNS-320 1.0.2
Timeline
- 2026-07-21: disclosed: Public disclosure of the vulnerability and exploit.
- 2026-07-21: advisory