Executive brief
D-Link DNS ShareCenter is a network-attached storage appliance used for file sharing and backup in small to medium businesses. The ISO Image Handler component contains a remote OS command injection vulnerability in the isomount_mgr.cgi script that allows unauthenticated attackers to execute arbitrary commands on the device, leading to complete system compromise and potential data theft or destruction.
Technical details
The vulnerability is an OS command injection flaw in the /cgi-bin/isomount_mgr.cgi script within the ISO Image Handler component. The upIsoRootPath parameter is not properly sanitized, allowing an attacker to inject shell metacharacters and execute arbitrary OS commands remotely without authentication. The attack vector is network-based, requiring only network connectivity to the affected device. A successful exploit grants the attacker command execution with the privileges of the web server process, potentially allowing full system control. The vulnerability affects D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 devices up to firmware version 20260717; patch availability has not been confirmed in the advisory.
Affected products
- D-Link DNS-320L up to 20260717
- D-Link DNS-327L up to 20260717
- D-Link DNS-340L up to 20260717
- D-Link DNS-345 up to 20260717
Timeline
- 2026-08-31: disclosed: Vulnerability published and exploit made public