Impact
A flaw exists in the /web/jquery/uploader/multi_uploadify.php component of D‑Link DNS‑320 firmware 1.0.2. By manipulating the Filedata[] argument, an attacker can upload arbitrary files without restriction. The CVE description notes that remote exploitation of the attack is possible, implying the attacker could place a script or executable that may later be served or executed by the device’s web server. The vulnerability is associated with improper authentication (CWE‑284) and unrestricted file upload (CWE‑434).
Affected Systems
The affected devices are D‑Link DNS‑320 units running firmware version 1.0.2. The vulnerability is confined to this specific release, as no other firmware revisions are cited as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1 % shows a low current exploitation probability. The CVE is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by sending a crafted HTTP POST request that provides a Filedata[] payload to the upload endpoint. If the upload succeeds, the attacker can place malicious files in a location that is accessible by the web server, potentially enabling further exploitation (inferred).
OpenCVE Enrichment