Impact
A vulnerability exists in the ISO Image Handler component of D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 routers. An attacker can manipulate the upIsoRootPath argument in the /cgi-bin/isomount_mgr.cgi script, causing the system to execute arbitrary shell commands. This flaw is a classic operating‑system command injection, enabling remote code execution on the device's underlying firmware. The weakness aligns with CWE‑78; it also falls under the broader category of CWE‑77, as it involves unsafe use of command‑line arguments.
Affected Systems
The affected hardware originates from D-Link and includes models DNS‑320L, DNS‑327L, DNS‑340L, and DNS‑345. Firmware versions up to 2026‑07‑17 are vulnerable; any device running such firmware inherits the remote command injection risk. No other versions or firmware families are listed as impacted.
Risk and Exploitability
The CVSS base score of 9.4 signals a critical risk. Although an EPSS rating is currently unavailable, the public availability of the exploit and the remote nature of the attack suggest a non‑negligible chance of real‑world abuse. The vulnerability has not yet been catalogued in the CISA KEV list. An attacker can reach the affected endpoint from the internet or local network, send a crafted upIsoRootPath value, and execute arbitrary commands with the privileges of the web server process, potentially compromising the router and enabling further lateral movement.
OpenCVE Enrichment