Junglewise Threat Intelligence

CVE-2026-16332: D-Link DNS-320 unrestricted file upload in multi_uploadify.php

CVE-2026-16332 · Severity: high · CVSS 7.3 · Published 2026-07-21

Vendors: D-Link.

Executive brief

A vulnerability exists in the D-Link DNS-320 storage device that allows unauthorized users to upload files to the system. This device is commonly used for network-attached storage (NAS) to manage and share data. An attacker could exploit this flaw to place malicious files on the device, potentially leading to a full system compromise or data loss.

Technical details

An unrestricted file upload vulnerability exists in D-Link DNS-320 version 1.0.2. The flaw is located within the /mydlink/multi_uploadify.php script, specifically involving improper validation of the 'Filedata[]' argument. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to upload arbitrary files to the server. This can lead to remote code execution if the attacker uploads a web shell or other executable script. Public exploit code is reportedly available.

Affected products

  • D-Link DNS-320 1.0.2

Timeline

  • 2026-07-21: disclosed: Vulnerability published on NVD/VulDB

References