Description
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-07-21
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the save_ajax.php script of D‑Link DNS‑320 firmware 1.0.2. By manipulating the "Malicious Handler" parameter, an attacker can upload arbitrary files without any restrictions on file type. This capability could place potentially harmful files onto the device; however, the description does not explicitly confirm that such uploads lead to code execution, so the risk remains theoretically possible but not proven.

Affected Systems

D‑Link DNS‑320 firmware version 1.0.2. No other firmware releases are mentioned in the advisory, indicating the flaw is specific to this build and device model.

Risk and Exploitability

The CVSS base score is 6.9, indicating moderate severity. The EPSS score is reported as below 1 %, implying a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. The advisory states the attack can be executed remotely, and the likely attack vector, based on the description, is a crafted HTTP request to /web/function/save_ajax.php. No authentication or privileged access is mentioned, suggesting the attack requires only network connectivity to the device.

Generated by OpenCVE AI on August 1, 2026 at 07:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DNS‑320 firmware to the latest release that fixes the unrestricted upload flaw.
  • If a firmware update is not immediately available, block or disable access to /web/function/save_ajax.php using the device’s firewall or ACL settings.
  • Configure the device to accept only approved file types for uploads and set the upload directory to the lowest privilege level to prevent execution of unwanted files.
  • Monitor system logs for upload attempts and investigate any anomalies.

Generated by OpenCVE AI on August 1, 2026 at 07:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Title D-Link DNS-320 save_ajax.php unrestricted upload
First Time appeared D-link
D-link dns-320
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:h:d-link:dns-320:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-320
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-22T14:15:55.059Z

Reserved: 2026-07-20T17:50:32.688Z

Link: CVE-2026-16331

cve-icon Vulnrichment

Updated: 2026-07-22T14:15:50.400Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:15:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type