Junglewise Threat Intelligence

CVE-2026-16448: D-Link NAS and NVR command injection in remote_backup.cgi

CVE-2026-16448 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: D-Link DNR-202L, D-Link DNS-315L, D-Link DNS-120. Vendors: D-Link.

Executive brief

A security vulnerability exists in several D-Link Network Attached Storage (NAS) and Network Video Recorder (NVR) devices. These devices are used to store files and manage security camera footage. An attacker could exploit this flaw to execute unauthorized commands on the device, potentially leading to data theft, service disruption, or full system compromise. Public exploit code is currently available, increasing the risk of an attack.

Technical details

A command injection vulnerability exists in the 'cgi_check_rsync_rw' function within the '/cgi-bin/remote_backup.cgi' file of various D-Link NAS and NVR models. The vulnerability is triggered by improper sanitization of the 'ip' argument. A remote attacker with low privileges can manipulate this parameter to inject and execute arbitrary system commands on the underlying operating system. The exploit has been publicly disclosed, and the vulnerability affects firmware versions up to 20260205. No official patch is currently noted in the advisory, though these devices are often legacy products.

Affected products

  • D-Link DNS-120 up to 20260205
  • D-Link DNR-202L up to 20260205
  • D-Link DNS-315L up to 20260205
  • D-Link DNS-320 up to 20260205
  • D-Link DNS-320L/LW up to 20260205
  • D-Link DNS-321/323/325/326/327L up to 20260205
  • D-Link DNR-322L/326 up to 20260205
  • D-Link DNS-340L/343/345 up to 20260205
  • D-Link DNS-726-4/1100-4/1200-05/1550-04 up to 20260205

Timeline

  • 2026-07-21: advisory: Initial publication of the vulnerability details.

References