Impact
The vulnerability is located in the save_ajax.php script of D‑Link DNS‑320 firmware 1.0.2. By manipulating the "Malicious Handler" parameter, an attacker can upload arbitrary files without any restrictions on file type. This capability could place potentially harmful files onto the device; however, the description does not explicitly confirm that such uploads lead to code execution, so the risk remains theoretically possible but not proven.
Affected Systems
D‑Link DNS‑320 firmware version 1.0.2. No other firmware releases are mentioned in the advisory, indicating the flaw is specific to this build and device model.
Risk and Exploitability
The CVSS base score is 6.9, indicating moderate severity. The EPSS score is reported as below 1 %, implying a low probability of widespread exploitation. The flaw is not listed in the CISA KEV catalog. The advisory states the attack can be executed remotely, and the likely attack vector, based on the description, is a crafted HTTP request to /web/function/save_ajax.php. No authentication or privileged access is mentioned, suggesting the attack requires only network connectivity to the device.
OpenCVE Enrichment