Impact
A vulnerability has been identified in the CGI handler of certain D‑Link routers, where an attacker can manipulate the f_ups_ip argument in the usb_device.cgi script to inject arbitrary operating‑system commands. This flaw allows the execution of commands with the privileges of the router firmware, effectively giving the attacker remote code execution capability. The attack may be carried out from a remote location, as indicated by the reference that the attack can be performed from remote.
Affected Systems
The affected devices are D‑Link DNS‑320L, DNS‑327L, DNS‑340L, and DNS‑345 models, up to firmware release 20260717. All four models share the vulnerable /cgi‑bin/usb_device.cgi component that processes the f_ups_ip parameter.
Risk and Exploitability
The CVSS score of 9.4 signals a critical severity, and although the EPSS score is not published, the flaw can be exploited remotely without authentication. Because the vulnerability is publicly disclosed and no KEV listing exists, the likelihood of exploitation remains high for devices that remain unpatched. The primary vector is a crafted HTTP request to the usb_device.cgi handler.
OpenCVE Enrichment