Description
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Published: 2026-08-31
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to inject arbitrary operating‑system commands through the alias, username, password, or volume_location parameters of the iscsi_mgr.cgi script on D‑Link DNS‑340L and DNS‑345 routers. The flaw arises from lack of input validation, a classic command‑injection weakness. If exploited, the attacker can execute any system command, achieving full control of the affected device, with potential compromise of the underlying network infrastructure.

Affected Systems

The affected products are the D‑Link DNS‑340L and DNS‑345 routers, up to firmware version 20260717. No other version or model information is provided in the official data.

Risk and Exploitability

The CVSS score of 9.4 indicates a critical severity and the EPSS score is not available, leaving the exploitation probability undefined in the data. The vulnerability is not listed in the CISA KEV catalog at this time. Based on the description, the attack vector is remote, accessed via the web interface that hosts the iscsi_mgr.cgi script. An external attacker can manipulate the exposed CGI arguments to execute arbitrary OS commands, provided the device exposes the web interface to an attacker.

Generated by OpenCVE AI on August 31, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from D‑Link that removes the insecure handling of iscsi_mgr.cgi parameters or upgrade to a version released after 20260717
  • If no update is available, roll back or eliminate exposure by disabling or blocking web to /cgi‑bin/iscsi_mgr.cgi
  • Implement network segmentation and firewall rules to limit the router’s exposure to untrusted clients and monitor for anomalous command‑injection attempts

Generated by OpenCVE AI on August 31, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Title D-Link DNS-340L/DNS-345 iscsi_mgr.cgi os command injection
First Time appeared D-link
D-link dns-340l
D-link dns-345
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
cpe:2.3:h:d-link:dns-345:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-340l
D-link dns-345
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-31T12:00:12.435Z

Reserved: 2026-08-30T17:35:39.301Z

Link: CVE-2026-82692

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T13:18:29.387

Modified: 2026-08-31T13:18:29.387

Link: CVE-2026-82692

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T13:30:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')