Impact
A flaw in the /cgi-bin/ve_mgr.cgi component of D‑Link DNS‑327L and DNS‑340L routers allows an attacker to supply a crafted f_dev argument that is executed as an operating‑system command on the device. The vulnerability "manipulation of the argument f_dev causes os command injection" can be triggered remotely, enabling an attacker to run arbitrary shell commands, compromise device integrity, and potentially pivot to other network assets. The issue is described as affecting firmware versions up to 20260717 and has published exploits that could be utilized in the wild.
Affected Systems
Affected devices include D‑Link DNS‑327L and D‑Link DNS‑340L routers that are running firmware released on or before 17 July 2026. No specific minor version numbers are listed, but any device with firmware dated 20260717 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity with a remote attack vector and high impact. The EPSS score is not available, but public exploits have been released, indicating that remote exploitation is feasible. The vulnerability is not yet listed in CISA’s KEV catalog, but its high score and known exploitability elevate the risk to network operators that expose these devices to the internet.
OpenCVE Enrichment