Executive brief
D-Link DNS-327L and DNS-340L are network storage devices used in small offices and homes. A remote attacker can inject arbitrary operating system commands through a vulnerable web interface, allowing complete takeover of the device without authentication. This could compromise stored data, disrupt network operations, or serve as a foothold for further attacks.
Technical details
This is an OS command injection vulnerability in the /cgi-bin/ve_mgr.cgi web interface. The vulnerability exists in the handling of the "f_dev" parameter, which fails to properly sanitize user input before passing it to system commands. An attacker can exploit this flaw remotely without authentication by crafting a malicious request containing shell metacharacters in the f_dev argument. Successful exploitation allows arbitrary command execution with device privileges. Affected versions extend to at least 20260717; patch availability status is unclear.
Affected products
- D-Link DNS-327L up to 20260717
- D-Link DNS-340L up to 20260717
Timeline
- 2026-08-31: disclosed