Sceawere
Vulnerability Detail
CVE-2026-82690UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
D-Link Remote OS Command Injection
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 18h ago
- Vendor
- D-Link
- Product
- DNS-327L
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-08-31T12:17:57.977Z",
"pubdate": "2026-08-31T12:17:57.977Z",
"executiveSummary": "A critical remote OS command injection vulnerability exists within the /cgi-bin/ve_mgr.cgi script of D-Link DNS-327L and DNS-340L devices.\nThe flaw stems from improper input validation of the f_dev parameter, allowing unauthenticated remote attackers to execute arbitrary system commands with elevated privileges.\nBy manipulating the vulnerable argument, an attacker can bypass security controls to achieve full system compromise.\nThe vulnerability is currently exposed to public exploit code, significantly increasing the risk of opportunistic exploitation.\nSuccessful exploitation facilitates unauthorized code execution, potential data exfiltration, and complete loss of device integrity.\nAffected products include D-Link DNS-327L and DNS-340L versions up to 20260717.",
"technicalDetails": "The vulnerability is classified as an OS Command Injection, residing in the binary or script handling the /cgi-bin/ve_mgr.cgi endpoint on affected D-Link NAS devices.\nThe root cause is the insecure handling of the f_dev parameter during HTTP GET or POST requests. The application fails to sanitize user-supplied input before passing it to a system-level function or a shell execution context.\nIn a typical attack flow, the attacker sends a crafted HTTP request to the /cgi-bin/ve_mgr.cgi script. By injecting shell metacharacters (e.g., semicolons, pipes, or backticks) into the f_dev argument, the attacker can break out of the intended logic and append arbitrary system commands.\nBecause the web server process typically runs with high privileges (often root) to perform administrative management tasks on the NAS, the injected commands are executed with these same privileges.\nThe exploitation process does not require prior authentication, making the device accessible to any entity with network reach to the management interface. The exploit facilitates remote code execution (RCE) by leveraging the lack of input filtering or character escaping mechanisms.\nPost-exploitation, the attacker gains the ability to interact with the underlying Linux operating system. This includes, but is not limited to, modification of configuration files, installation of persistent backdoors, data extraction from attached storage volumes, and participation in botnets.\nThe vulnerability persists across all firmware versions up to 20260717, indicating a legacy issue in the input validation logic of the management CGI scripts.\nBecause the exploit is published, the barrier to entry for attackers is extremely low. Attackers can deploy automated scripts to scan for and compromise vulnerable devices globally, leading to potential widespread exploitation of these network-attached storage units."
}