Executive brief
A security vulnerability has been identified in the D-Link DNS-320, a network-attached storage (NAS) device used for data backup and file sharing. An attacker can remotely upload unauthorized files to the device without needing a password. This could allow a malicious actor to compromise the device, potentially leading to data theft, service disruption, or a foothold for further attacks on the local network.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in the D-Link DNS-320 NAS device running firmware version 1.0.2. The flaw is located in the '/web/jquery/uploader/multi_uploadify.php' file due to improper validation of the 'Filedata[]' argument. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to the web server. This can lead to remote code execution (RCE) if the attacker uploads a malicious script (e.g., a PHP shell) and executes it. Public exploit code has been disclosed.
Affected products
- D-Link DNS-320 1.0.2
Timeline
- 2026-07-21: advisory: Initial disclosure via VulDB and NVD