Impact
A flaw in the uploadify.php script on the D-Link DNS-320 1.0.2 firmware allows an adversary to manipulate the Malicious Handler argument and upload arbitrary files without restriction. This weakness could enable an attacker to place executable or script files on the device, potentially leading to remote code execution or additional privilege escalation. The vulnerability is tied to the absence of proper input validation and access control, as identified by CWE-434 and CWE-284.
Affected Systems
The affected product is the D-Link DNS-320 router running firmware version 1.0.2. No other versions or products are listed as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, but the EPSS score of less than 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via the web interface, as the flaw resides in an externally accessible script and a publicly available exploit has been noted.
OpenCVE Enrichment