Impact
The vulnerability is located in the file /web/jquery/uploader/uploadify.php on the D‑Link DNS‑320 firmware 1.0.2. An attacker can manipulate an argument to that script in order to upload arbitrary files without restriction. The CVE description states that remote exploitation is possible and that a public exploit is available, but it does not explicitly claim execution of uploaded code. Based on the description, it is inferred that uploading arbitrary files could potentially allow further manipulation of the device via the uploaded content, although the CVE does not explicitly confirm that uploaded code can be executed.
Affected Systems
D‑Link DNS‑320 devices running firmware version 1.0.2 are affected. No other firmware builds are listed in the current advisory.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity for a remote vulnerability that permits the upload of arbitrary files. EPSS of <1% indicates that, as of this analysis, the exploitation probability is very low and the flaw is not listed in the CISA KEV catalog. Likely attackers would target devices exposed to remote management interfaces or the local network, exploiting the lack of proper access control (CWE‑284) and the untrusted file upload handling (CWE‑434). While the likelihood remains low, the availability of a public exploit and the potential impact of unrestricted uploads warrant early remediation for exposed devices.
OpenCVE Enrichment