Junglewise Threat Intelligence

CVE-2026-82692: D-Link DNS-340L and DNS-345 OS command injection in iscsi_mgr.cgi

CVE-2026-82692 · Severity: critical · CVSS 9.9 · Published 2026-08-31

Executive brief

D-Link DNS-340L and DNS-345 are network-attached storage (NAS) devices used to provide centralized file storage and backup for businesses. A critical vulnerability in the iSCSI management interface allows unauthenticated remote attackers to inject arbitrary operating system commands by manipulating parameters, potentially leading to complete system compromise, data theft, or service disruption.

Technical details

This is an OS command injection vulnerability in the /cgi-bin/iscsi_mgr.cgi script on D-Link DNS-340L and DNS-345 NAS devices. The vulnerability exists in the handling of parameters such as alias, username, password, and volume_location, which are passed unsanitized to shell commands. An attacker can craft malicious input containing shell metacharacters to execute arbitrary commands with the privileges of the web server process. The attack is remotely exploitable over the network and does not require authentication. A public proof-of-concept has been released, increasing the risk of widespread exploitation.

Affected products

  • D-Link DNS-340L up to 20260717
  • D-Link DNS-345 up to 20260717

Timeline

  • 2026-08-31: disclosed: Vulnerability publicly disclosed
  • 2026-08-31: other: Public proof-of-concept exploit released

References

Related threats