Impact
A vulnerability exists in the Virtual Volume Handler of D‑Link DNS‑340L and DNS‑345 routers. Manipulating the CGI parameters f_sharename, f_target, and f_name in /cgi-bin/virtual_vol.cgi allows an attacker to inject operating‑system commands. Consequently, an attacker can execute arbitrary commands on the router’s firmware when sending a crafted HTTP request.
Affected Systems
The flaw affects D‑Link DNS‑340L and DNS‑345 devices running firmware versions 1.01B04, 1.03B06, 1.04.B02, and 1.05b04. The vulnerable component is the virtual_vol.cgi script in the Virtual Volume Handler.
Risk and Exploitability
The CVSS score of 9.4 classifies this as critical, and the EPSS score of 3% indicates a non‑negligible prospect of exploitation. The vulnerability is not listed in CISA’s KEV catalog, yet it has been publicly disclosed and can be exploited remotely via HTTP requests. Exploitation would enable an attacker to run arbitrary system commands on the affected router without authentication.
OpenCVE Enrichment