Executive brief
D-Link DNS-340L is a network-attached storage device. A remote attacker can inject arbitrary operating system commands through the dropbox.cgi web interface by manipulating the callback_url or sync_interval parameters, potentially gaining complete control of the device and accessing all stored data.
Technical details
This is an OS command injection vulnerability in the CGI Handler component of D-Link DNS-340L firmware version 1.01B04. The vulnerable endpoint /cgi-bin/dropbox.cgi fails to properly sanitize user-supplied input in the callback_url and sync_interval parameters before passing them to system commands. The attack is network-reachable and requires no authentication. An attacker can execute arbitrary shell commands with the privileges of the web server process, typically leading to full device compromise. A public exploit exists for this vulnerability.
Affected products
- D-Link DNS-340L 1.01B04
Timeline
- 2026-09-03: disclosed
- other: Exploit made public