Impact
The D‑Link DNS‑340L router contains an OS command injection flaw in the CGI handler /cgi-bin/dropbox.cgi. By supplying a malicious value for the callback_url or sync_interval parameters, an attacker can execute arbitrary operating‑system commands. This flaw can be triggered remotely from any host that can reach the router's web interface, granting the attacker full control of the device and undermining all network traffic handled by the router.
Affected Systems
Only the D‑Link DNS‑340L routers running firmware version 1.01B04 are affected. The vulnerability resides in the router’s web‑interface component dropbox.cgi and is not known to impact other model series or firmware releases.
Risk and Exploitability
The CVSS score of 9.4 categorizes the vulnerability as critical, while the EPSS score of 3% indicates a low probability of exploitation at this time. The public availability of exploit code and the remote nature of the attack raise the overall risk, and the absence of a CISA KEV listing does not reduce the threat posture. Successful exploitation would allow an attacker to run any command on the router, potentially gaining persistence, exfiltrating data, or pivoting to adjacent devices.
OpenCVE Enrichment