Executive brief
A security vulnerability exists in the D-Link DNS-320 ShareCenter, a network-attached storage (NAS) device used for data backup and file sharing. An attacker with administrative access can execute unauthorized system commands on the device. This could lead to a complete compromise of the storage system, allowing the attacker to view, modify, or delete sensitive files and disrupt network operations.
Technical details
Multiple OS command injection vulnerabilities exist in the D-Link DNS-320 firmware version 2.06B01. The flaws are located within several CGI binaries, including system_mgr.cgi, account_mgr.cgi, dsk_mgr.cgi, and app_mgr.cgi. Specifically, functions such as cgi_set_host, cgi_set_ntp, and cgi_fan_control fail to properly sanitize user-supplied input before passing it to system shell commands (e.g., via /bin/hostname or sntp). An attacker with network access and administrative (high) privileges can exploit these vulnerabilities by sending crafted POST requests to the affected CGI endpoints. Successful exploitation allows for arbitrary command execution with the privileges of the web server. While the reported CVSS is 4.7 (Medium) due to the requirement for high privileges, some sources suggest a higher impact (8.8) depending on the environment.
Affected products
- D-Link DNS-320 ShareCenter NAS (Rev.A) Firmware 2.06B01
Timeline
- 2026-05-11: advisory: CVE-2026-8273 published by NVD/VulDB
References
- https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/D-Link%20DNS-320%20%20system_mgraccount_mgrdsk_mgrapp_mgr%20Multiple%20CGI%20OS%20Command%20Injection.md
- https://vuldb.com/submit/810082
- https://vuldb.com/vuln/362570
- https://vuldb.com/vuln/362570/cti
- https://www.dlink.com/