Description
A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Published: 2026-08-31
Score: 9.4 Critical
EPSS: 2.8% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in the Virtual Volume Handler of D‑Link DNS‑340L and DNS‑345 routers. Manipulating the CGI parameters f_sharename, f_target, and f_name in /cgi-bin/virtual_vol.cgi allows an attacker to inject operating‑system commands. Consequently, an attacker can execute arbitrary commands on the router’s firmware when sending a crafted HTTP request.

Affected Systems

The flaw affects D‑Link DNS‑340L and DNS‑345 devices running firmware versions 1.01B04, 1.03B06, 1.04.B02, and 1.05b04. The vulnerable component is the virtual_vol.cgi script in the Virtual Volume Handler.

Risk and Exploitability

The CVSS score of 9.4 classifies this as critical, and the EPSS score of 3% indicates a non‑negligible prospect of exploitation. The vulnerability is not listed in CISA’s KEV catalog, yet it has been publicly disclosed and can be exploited remotely via HTTP requests. Exploitation would enable an attacker to run arbitrary system commands on the affected router without authentication.

Generated by OpenCVE AI on September 1, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to an official release that fixes the command‑injection flaw, preferably the latest version from D‑Link.
  • If a firmware update is unavailable, block or remove the /cgi-bin/virtual_vol.cgi endpoint using the router’s firewall or access‑control mechanisms.
  • Restrict external access to the router’s administrative interfaces by applying an IP whitelist or placing the device in a non‑exposed network segment.

Generated by OpenCVE AI on September 1, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Title D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection
First Time appeared D-link
D-link dns-340l
D-link dns-345
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-345:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-340l
D-link dns-345
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-01T18:10:58.268Z

Reserved: 2026-08-30T17:35:22.464Z

Link: CVE-2026-82688

cve-icon Vulnrichment

Updated: 2026-09-01T17:08:17.817Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T11:16:40.353

Modified: 2026-09-01T19:17:28.907

Link: CVE-2026-82688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:45:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')