Impact
A flaw in the Add‑On Center on the D‑Link DNS‑340L allows an attacker to manipulate the f_name/f_url/f_flag/f_login_user parameters of /cgi-bin/addon_center.cgi, resulting in OS command injection. This vulnerability lets an unauthenticated remote user execute arbitrary commands on the device, compromising confidentiality, integrity, and availability of the router and any network resources it manages.
Affected Systems
D‑Link DNS‑340L firmware 1.01B04 is affected. The vulnerability is tied to the Add‑On Center component accessed via /cgi-bin/addon_center.cgi.
Risk and Exploitability
The CVSS score is 9.4, indicating a critical severity. The EPSS score is unknown, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is remote, relying on HTTP/HTTPS requests to the vulnerable CGI endpoint. An attacker can trigger the injection by sending specially crafted values for the mentioned parameters without needing authentication or prior access to the device.
OpenCVE Enrichment