Description
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Published: 2026-07-21
Score: 5.3 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection vulnerability exists in the cgi_check_rsync_rw function of /cgi-bin/remote_backup.cgi. By manipulating the ip parameter, an attacker can cause arbitrary shell commands to execute on the device. The flaw can be triggered remotely via the web interface.

Affected Systems

Affected hardware includes D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, and DNS-1550-04, all models running firmware versions up to and including 20260205.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. The EPSS score of 1% indicates a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited via the web interface by supplying a crafted ip value; the attack can be performed remotely.

Generated by OpenCVE AI on August 4, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update firmware to a version that contains the remote_backup.cgi patch for affected models.
  • If an update is not yet available, disable the remote backup feature or restrict the web interface to trusted IP addresses.
  • Apply network segmentation or firewall rules to block external access to the DNS device’s web management interface.
  • Monitor logs for unexpected calls to /cgi-bin/remote_backup.cgi.

Generated by OpenCVE AI on August 4, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Title D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
First Time appeared D-link
D-link dnr-202l
D-link dnr-322l
D-link dnr-326
D-link dns-1100-4
D-link dns-120
D-link dns-1200-05
D-link dns-1550-04
D-link dns-315l
D-link dns-320
D-link dns-320l
D-link dns-320lw
D-link dns-321
D-link dns-323
D-link dns-325
D-link dns-326
D-link dns-327l
D-link dns-340l
D-link dns-343
D-link dns-345
D-link dns-726-4
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:d-link:dnr-202l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dnr-322l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dnr-326:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-1100-4:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-1200-05:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-120:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-1550-04:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-315l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-320:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-320l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-320lw:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-321:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-323:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-325:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-326:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-327l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-343:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-345:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-726-4:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dnr-202l
D-link dnr-322l
D-link dnr-326
D-link dns-1100-4
D-link dns-120
D-link dns-1200-05
D-link dns-1550-04
D-link dns-315l
D-link dns-320
D-link dns-320l
D-link dns-320lw
D-link dns-321
D-link dns-323
D-link dns-325
D-link dns-326
D-link dns-327l
D-link dns-340l
D-link dns-343
D-link dns-345
D-link dns-726-4
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dnr-202l Dnr-322l Dnr-326 Dns-1100-4 Dns-120 Dns-1200-05 Dns-1550-04 Dns-315l Dns-320 Dns-320l Dns-320lw Dns-321 Dns-323 Dns-325 Dns-326 Dns-327l Dns-340l Dns-343 Dns-345 Dns-726-4
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-21T14:55:10.371Z

Reserved: 2026-07-21T08:49:25.085Z

Link: CVE-2026-16448

cve-icon Vulnrichment

Updated: 2026-07-21T14:52:49.776Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')