Junglewise Threat Intelligence

CVE-2026-85223: D-Link DNS-340L OS command injection in dropbox.cgi

CVE-2026-85223 · Severity: critical · CVSS 9.9 · Published 2026-09-03

Executive brief

D-Link DNS-340L is a network-attached storage device. A remote attacker can inject arbitrary operating system commands through the dropbox.cgi web interface by manipulating the callback_url or sync_interval parameters, potentially gaining complete control of the device and accessing all stored data.

Technical details

This is an OS command injection vulnerability in the CGI Handler component of D-Link DNS-340L firmware version 1.01B04. The vulnerable endpoint /cgi-bin/dropbox.cgi fails to properly sanitize user-supplied input in the callback_url and sync_interval parameters before passing them to system commands. The attack is network-reachable and requires no authentication. An attacker can execute arbitrary shell commands with the privileges of the web server process, typically leading to full device compromise. A public exploit exists for this vulnerability.

Affected products

  • D-Link DNS-340L 1.01B04

Timeline

  • 2026-09-03: disclosed
  • other: Exploit made public

References

Related threats