CVE-2026-82689
Received
Received - Intake
OS Command Injection in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345
Vulnerability report for CVE-2026-82689, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-31
Last updated on: 2026-08-31
Assigner: VulDB
Description
Description
A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| d-link | dns-320l | to 20260717 (inc) |
| d-link | dns-327l | to 20260717 (inc) |
| d-link | dns-340l | to 20260717 (inc) |
| d-link | dns-345 | to 20260717 (inc) |
| d-link | dns-320l | * |
| d-link | dns-327l | * |
| d-link | dns-340l | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-77 | The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. |
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |