Impact
A command injection vulnerability exists in the cgi_check_rsync_rw function of /cgi-bin/remote_backup.cgi. By manipulating the ip parameter, an attacker can cause arbitrary shell commands to execute on the device. The flaw can be triggered remotely via the web interface.
Affected Systems
Affected hardware includes D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, and DNS-1550-04, all models running firmware versions up to and including 20260205.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score of 1% indicates a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited via the web interface by supplying a crafted ip value; the attack can be performed remotely.
OpenCVE Enrichment