Junglewise Threat Intelligence

CVE-2026-82690: D-Link DNS-327L and DNS-340L OS command injection in ve_mgr.cgi

CVE-2026-82690 · Severity: critical · CVSS 9.1 · Published 2026-08-31

Executive brief

D-Link DNS-327L and DNS-340L are network storage devices used in small offices and homes. A remote attacker can inject arbitrary operating system commands through a vulnerable web interface, allowing complete takeover of the device without authentication. This could compromise stored data, disrupt network operations, or serve as a foothold for further attacks.

Technical details

This is an OS command injection vulnerability in the /cgi-bin/ve_mgr.cgi web interface. The vulnerability exists in the handling of the "f_dev" parameter, which fails to properly sanitize user input before passing it to system commands. An attacker can exploit this flaw remotely without authentication by crafting a malicious request containing shell metacharacters in the f_dev argument. Successful exploitation allows arbitrary command execution with device privileges. Affected versions extend to at least 20260717; patch availability status is unclear.

Affected products

  • D-Link DNS-327L up to 20260717
  • D-Link DNS-340L up to 20260717

Timeline

  • 2026-08-31: disclosed

References

Related threats