Executive brief
The D-Link DNS-340L is a network-attached storage device. The Add-On Center web interface contains an OS command injection vulnerability in the addon_center.cgi script that allows remote attackers to execute arbitrary system commands without authentication, potentially compromising the device and any data stored on it.
Technical details
A command injection vulnerability exists in the /cgi-bin/addon_center.cgi file of the D-Link DNS-340L Add-On Center component. The vulnerability is triggered through manipulation of the f_name, f_url, f_flag, and f_login_user parameters. The attack is remotely exploitable without requiring authentication. An attacker can inject arbitrary OS commands which will be executed with the privileges of the web server process, allowing full device compromise. The exploit code has been publicly disclosed.
Affected products
- D-Link DNS-340L 1.01B04
Timeline
- 2026-09-03: disclosed