CVE-2026-82689
Received Received - Intake

OS Command Injection in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345

Vulnerability report for CVE-2026-82689, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulDB

Description

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
d-link dns-320l to 20260717 (inc)
d-link dns-327l to 20260717 (inc)
d-link dns-340l to 20260717 (inc)
d-link dns-345 to 20260717 (inc)
d-link dns-320l *
d-link dns-327l *
d-link dns-340l *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82689 is an OS command injection vulnerability in D-Link ShareCenter NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345). The flaw exists in the isomount_mgr.cgi CGI handler where the upIsoRootPath parameter is improperly sanitized. Attackers can inject shell commands via this parameter, allowing remote command execution as the CGI process user.

Detection Guidance

Check if any of the affected D-Link models (DNS-320L, DNS-327L, DNS-340L, DNS-345) are accessible via web interface. Inspect HTTP POST requests to /cgi-bin/isomount_mgr.cgi for the parameter upIsoRootPath. Look for unusual shell metacharacters or commands in logs or network traffic.

Impact Analysis

This vulnerability allows authenticated attackers to execute arbitrary commands on the device. Impact includes creating/modifying files, altering NAS configurations, accessing stored data, disrupting services, or using the device as a network foothold for further attacks.

Compliance Impact

This vulnerability allows authenticated attackers to execute arbitrary commands on affected D-Link NAS devices. Such remote command execution could lead to unauthorized access to sensitive data, data exfiltration, or data manipulation, which directly violates compliance requirements under GDPR (data protection) and HIPAA (protected health information).

Mitigation Strategies

Disable remote web management access to the NAS devices. Block external access to /cgi-bin/isomount_mgr.cgi via firewall rules. Update firmware to the latest patched version if available. Monitor network traffic for suspicious POST requests to the vulnerable endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82689. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart