Junglewise Threat Intelligence

CVE-2026-85222: D-Link DNS-340L OS command injection in addon_center.cgi

CVE-2026-85222 · Severity: critical · CVSS 9.1 · Published 2026-09-03

Executive brief

The D-Link DNS-340L is a network-attached storage device. The Add-On Center web interface contains an OS command injection vulnerability in the addon_center.cgi script that allows remote attackers to execute arbitrary system commands without authentication, potentially compromising the device and any data stored on it.

Technical details

A command injection vulnerability exists in the /cgi-bin/addon_center.cgi file of the D-Link DNS-340L Add-On Center component. The vulnerability is triggered through manipulation of the f_name, f_url, f_flag, and f_login_user parameters. The attack is remotely exploitable without requiring authentication. An attacker can inject arbitrary OS commands which will be executed with the privileges of the web server process, allowing full device compromise. The exploit code has been publicly disclosed.

Affected products

  • D-Link DNS-340L 1.01B04

Timeline

  • 2026-09-03: disclosed

References

Related threats