Impact
A vulnerability in D‑Link DNS‑320 allows an attacker to upload arbitrary files by manipulating the Filedata[] argument in the /mydlink/multi_uploadify.php script. This is an instance of CWE‑434 (Unrestricted Upload of File with Dangerous Type) combined with weak access control (CWE‑284). If a malicious file such as a web shell is uploaded, the compromised device could be used to execute arbitrary code, exfiltrate data or serve malicious content. The consequence is a loss of confidentiality, integrity, and availability on the affected device.
Affected Systems
The flaw is present in the D‑Link DNS‑320 model running firmware version 1.0.2. No other vendors or versions are listed, so the impact is limited to that specific device model and firmware release.
Risk and Exploitability
The CVSS score of 6.9 places this vulnerability in the medium severity range. The EPSS score of below 1% suggests that public exploitation is currently unlikely, but the fact that the exploit is published and the vulnerability can be triggered remotely means that attackers with the right motivation could still target the device. The vulnerability is not listed in CISA KEV, indicating no known widespread compromises, but the remote upload capability means that a single attacker could gain code execution if the device is exposed to the internet. The attack vector is inferred to be remote via the web interface, requiring network access to the device.
OpenCVE Enrichment