Impact
The vulnerability arises in the upload.php script of the D‑Link DNS‑320 appliance, allowing an attacker to craft a request that provides an arbitrary File parameter. This leads to an unrestricted file upload, enabling the attacker to place potentially executable files on the system. The resulting upload bypasses any intended file type checks or size restrictions, which could be leveraged to upload malicious code and execute arbitrary commands, thereby compromising confidentiality, integrity, or availability of the device. Based on the description, it is inferred that an attacker could exploit the unrestricted upload to upload and subsequently execute malicious code, though the description provided does not explicitly state this.
Affected Systems
Affected products are the D‑Link DNS‑320 network attached storage appliance, specifically firmware version 1.0.2. No other versions are confirmed, and the vulnerability is associated with the web_file upload module exposed via /web/web_file/upload.php.
Risk and Exploitability
The CVSS v3 score of 6.9 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV database. The attack vector is remote, with an attacker able to send a crafted HTTP request over the network to the device. Successful exploitation would grant the attacker the ability to upload files without restrictions; based on the description, it is inferred that if the uploaded payload subsequently triggered, this could lead to remote code execution.
OpenCVE Enrichment