Executive brief
D-Link DNS-320 ShareCenter is a network-attached storage (NAS) device used for centralized file sharing and backup. A vulnerability in its web management interface allows an authenticated attacker to inject arbitrary operating system commands, potentially leading to complete device compromise, data theft, and lateral movement into the network.
Technical details
The vulnerability is an OS command injection (CWE-78) in the /cgi/file_sharing.cgi component affecting D-Link DNS-320 ShareCenter firmware version 2.06B01. The file sharing CGI constructs a shell command using the attacker-controlled fileurl parameter without proper sanitization. By injecting shell metacharacters and quotes in the fileurl argument (e.g., `cmd=3&fileurl=X";:>/tmp/pwn;#`), an authenticated attacker can break out of the intended URL argument and execute arbitrary commands via `/bin/sh -c` with the privileges of the web/CGI runtime. The attack requires authentication to the device's web interface and network access; no user interaction is needed. Successful exploitation enables full device compromise, including arbitrary command execution, data access, persistence, and lateral movement within the NAS environment.
Affected products
- D-Link DNS-320 ShareCenter 2.06B01
Timeline
- 2026-09-03: disclosed
- 2026-09-03: advisory