Junglewise Threat Intelligence

CVE-2026-16331: D-Link DNS-320 unrestricted file upload in save_ajax.php

CVE-2026-16331 · Severity: high · CVSS 7.3 · Published 2026-07-21

Vendors: D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DNS-320 network storage device. This flaw allows an unauthorized person to upload files to the device remotely without proper restrictions. An attacker could use this to compromise the device, potentially leading to data theft, service disruption, or unauthorized access to the local network.

Technical details

An unrestricted file upload vulnerability exists in the D-Link DNS-320 NAS device running firmware version 1.0.2. The flaw is located in the /web/function/save_ajax.php file due to improper validation of the 'Malicious Handler' argument. A remote, unauthenticated attacker can exploit this vulnerability to upload arbitrary files to the system. This can lead to remote code execution if the attacker is able to upload and subsequently execute a web shell or other malicious script. Public exploit code has been disclosed.

Affected products

  • D-Link DNS-320 1.0.2

Timeline

  • 2026-07-21: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-07-21: advisory

References