Description
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Published: 2026-08-31
Score: 9.4 Critical
EPSS: 2.4% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows an attacker to inject arbitrary operating‑system commands through the alias, username, password, or volume_location parameters of the iscsi_mgr.cgi script on D‑Link DNS‑340L and DNS‑345 routers. The flaw arises from lack of input validation, a classic command‑injection weakness. If exploited, the attacker can execute any system command, achieving full control of the affected device, with potential compromise of the underlying network infrastructure.

Affected Systems

The affected products are the D‑Link DNS‑340L and DNS‑345 routers, up to firmware version 20260717. No other version or model information is provided in the official data.

Risk and Exploitability

The CVSS score of 9.4 indicates a critical severity and the EPSS score is 2%, indicating a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog at this time. Based on the description, the attack vector is remote, accessed via the web interface that hosts the iscsi_mgr.cgi script. An external attacker can manipulate the exposed CGI arguments to execute arbitrary OS commands, provided the device exposes the web interface to an attacker.

Generated by OpenCVE AI on September 1, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from D‑Link that removes the insecure handling of iscsi_mgr.cgi parameters or upgrade to a version released after 20260717
  • If no update is available, roll back or eliminate exposure by disabling or blocking web to /cgi‑bin/iscsi_mgr.cgi
  • Implement network segmentation and firewall rules to limit the router’s exposure to untrusted clients and monitor for anomalous command‑injection attempts

Generated by OpenCVE AI on September 1, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Title D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection
First Time appeared D-link
D-link dns-340l
D-link dns-345
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-345:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-340l
D-link dns-345
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T14:20:24.797Z

Reserved: 2026-08-30T17:35:39.301Z

Link: CVE-2026-82692

cve-icon Vulnrichment

Updated: 2026-08-31T14:20:20.678Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T13:18:29.387

Modified: 2026-08-31T20:56:08.800

Link: CVE-2026-82692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T15:45:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')