Sceawere

Vulnerability Detail

CVE-2026-82688UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link DNS OS Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
19h ago
Vendor
D-Link
Product
DNS-340L
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-31T11:16:40.353Z",
  "pubdate": "2026-08-31T11:16:40.353Z",
  "executiveSummary": "A critical OS command injection vulnerability exists within the Virtual Volume Handler component of D-Link DNS-340L and DNS-345 network-attached storage devices. The vulnerability resides in the /cgi-bin/virtual_vol.cgi script, which fails to properly sanitize user-supplied input provided via the f_sharename, f_target, or f_name arguments. This flaw allows a remote, unauthenticated attacker to inject and execute arbitrary system commands with the privileges of the web server process. Successful exploitation can lead to full device compromise, unauthorized access to stored data, lateral movement within the network, and the potential for persistent control of the affected hardware. Due to the public disclosure of exploit material, the risk of exploitation by malicious actors is elevated. The vulnerability affects multiple firmware versions including 1.01B04, 1.03B06, 1.04.B02, and 1.05b04.",
  "technicalDetails": "The vulnerability is classified as an OS command injection flaw originating from improper input validation within the Virtual Volume Handler of the D-Link DNS-340L and DNS-345 storage platforms. The vulnerable component is the /cgi-bin/virtual_vol.cgi script, which is responsible for managing virtual volume configurations. During the processing of HTTP GET or POST requests, the application accepts user-provided strings through the f_sharename, f_target, and f_name parameters. These parameters are subsequently concatenated into system shell commands without adequate sanitization, escaping, or neutralization of metacharacters such as backticks, semicolons, or pipe symbols.\nThe exploitation flow begins with the attacker crafting a malicious HTTP request targeting the /cgi-bin/virtual_vol.cgi endpoint. By embedding shell metacharacters and arbitrary commands into the f_sharename, f_target, or f_name fields, the attacker can break out of the intended command structure executed by the CGI script. When the server processes the request, the underlying operating system executes the attacker's injected command string. Because the web server process frequently operates with elevated or root-level privileges on these embedded devices, the attacker gains the ability to execute code with equivalent administrative control.\nThe technical impact involves the execution of arbitrary system commands, which allows the attacker to perform unauthorized file system operations, modify system configurations, retrieve sensitive configuration data, or install malicious persistence mechanisms such as web shells or backdoors. The exposure is categorized as remote, meaning an attacker does not require physical access to the device and can initiate the attack from any reachable network segment. The lack of robust input validation and command parameterization in the legacy CGI implementation serves as the primary root cause. Once the command injection is triggered, the attacker can leverage standard Unix command-line utilities to maintain a stable environment, exfiltrate data, or conduct further reconnaissance on the local area network, effectively bypassing standard authentication mechanisms that the web interface would otherwise enforce. The exploitation path does not require sophisticated bypasses, making it highly reliable for remote actors possessing the disclosed exploit details."
}
CVE-2026-82688: D-Link DNS OS Command Injection (CRITICAL Severity, CVSS: 9.1) - Sceawere