Description
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Published: 2026-09-03
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is in the D-Link DNS‑340L router’s CGI handler /cgi-bin/dropbox.cgi. A crafted request that modifies the callback_url or sync_interval parameters causes an OS command injection, allowing an attacker to execute arbitrary commands. The vulnerability is exploitable remotely and public exploit code is available.

Affected Systems

D-Link DNS‑340L routers running firmware 1.01B04 are affected. No other products or versions are listed.

Risk and Exploitability

The CVSS score of 9.4 marks this as critical. Although a public exploit exists, the EPSS score is not provided; nevertheless the lack of a KEV listing does not reduce the threat. The attack can be launched from any machine that can reach the router’s web interface. Successful exploitation would give the attacker full control over the device’s operating system.

Generated by OpenCVE AI on September 3, 2026 at 22:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest firmware revision that patches /cgi-bin/dropbox.cgi.
  • Restrict external access to the device’s management interface by applying firewall rules or placing the router in a trusted VLAN, allowing only internal or whitelisted IPs to reach port 80/443.
  • Disable the dropbox.cgi functionality or block HTTP requests to /cgi-bin/dropbox.cgi using router ACLs or an external firewall.

Generated by OpenCVE AI on September 3, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Title D-Link DNS-340L CGI dropbox.cgi os command injection
First Time appeared D-link
D-link dns-340l
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-340l
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-03T21:15:10.369Z

Reserved: 2026-09-03T14:24:33.078Z

Link: CVE-2026-85223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:24.080

Modified: 2026-09-03T22:18:24.080

Link: CVE-2026-85223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T22:30:10Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')