Impact
This vulnerability allows an attacker to inject arbitrary operating‑system commands through the alias, username, password, or volume_location parameters of the iscsi_mgr.cgi script on D‑Link DNS‑340L and DNS‑345 routers. The flaw arises from lack of input validation, a classic command‑injection weakness. If exploited, the attacker can execute any system command, achieving full control of the affected device, with potential compromise of the underlying network infrastructure.
Affected Systems
The affected products are the D‑Link DNS‑340L and DNS‑345 routers, up to firmware version 20260717. No other version or model information is provided in the official data.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity and the EPSS score is not available, leaving the exploitation probability undefined in the data. The vulnerability is not listed in the CISA KEV catalog at this time. Based on the description, the attack vector is remote, accessed via the web interface that hosts the iscsi_mgr.cgi script. An external attacker can manipulate the exposed CGI arguments to execute arbitrary OS commands, provided the device exposes the web interface to an attacker.
OpenCVE Enrichment