Impact
The vulnerability is located in the system_mgr.cgi CGI script on the D-Link DNS‑320 device. By sending crafted input to functions such as cgi_set_host, cgi_set_ntp, cgi_fan_control, or cgi_merge_user, an attacker can inject arbitrary operating‑system commands. This allows the execution of unintended commands on the device, potentially giving the attacker remote control of the router. The description explicitly states that the attack can be initiated remotely, indicating that an attacker does not need local access to exploit the flaw.
Affected Systems
The affected product is the D-Link DNS‑320 NAS/router running firmware version 2.06B01. The weakness is confined to the /cgi-bin/system_mgr.cgi file and its CGI functions. No other products or firmware versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.1 reflects medium severity, while the EPSS score of 5% indicates a moderate probability of exploitation under current conditions. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of active exploitation. The attack is likely to be conducted remotely over the device’s web interface; the available information does not provide explicit details about authentication requirements, so the attack vector is inferred to be remote and potentially unauthenticated or using default credentials.
OpenCVE Enrichment