Executive brief
A security vulnerability exists in D-Link DNS-320 ShareCenter storage devices, which are used to manage and store files on a network. An attacker can exploit this flaw to take complete control of the device by injecting malicious commands through file management features like deleting or renaming files. This could lead to the theft of sensitive data, loss of files, or the device being used as a foothold to attack other systems on the corporate network.
Technical details
Multiple OS command injection vulnerabilities exist in the /cgi-bin/webfile_mgr.cgi component of D-Link DNS-320 firmware version 2.06B01. The vulnerability is rooted in several functions (including cgi_del, cgi_rename, cgi_copy, cgi_move, cgi_chmod, and cgi_chown) that read path and filename parameters via cgiFormString() and improperly embed them into shell commands using sprintf() before passing them to the system() function. A remote attacker with low-privileged access can exploit this by sending a crafted POST request containing shell metacharacters (e.g., semicolons) in the 'path' parameter. Successful exploitation allows for arbitrary command execution with the privileges of the web server. While some sources report a lower CVSS, the technical analysis confirms a high-impact exploit path with public proof-of-concept code available.
Affected products
- D-Link DNS-320 ShareCenter NAS (Rev.A) 2.06B01
Timeline
- 2026-05-11: disclosed: Vulnerability published and CVE-2026-8272 assigned.
References
- https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/D-Link%20DNS-320%20webfile_mgr.cgi%20Multiple%20OS%20Command%20Injection%20via%20File%20Operations.md
- https://vuldb.com/submit/810079
- https://vuldb.com/vuln/362569
- https://vuldb.com/vuln/362569/cti
- https://www.dlink.com/