Description
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Published: 2026-09-03
Score: 9.4 Critical
EPSS: 3.3% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The D‑Link DNS‑340L router contains an OS command injection flaw in the CGI handler /cgi-bin/dropbox.cgi. By supplying a malicious value for the callback_url or sync_interval parameters, an attacker can execute arbitrary operating‑system commands. This flaw can be triggered remotely from any host that can reach the router's web interface, granting the attacker full control of the device and undermining all network traffic handled by the router.

Affected Systems

Only the D‑Link DNS‑340L routers running firmware version 1.01B04 are affected. The vulnerability resides in the router’s web‑interface component dropbox.cgi and is not known to impact other model series or firmware releases.

Risk and Exploitability

The CVSS score of 9.4 categorizes the vulnerability as critical, while the EPSS score of 3% indicates a low probability of exploitation at this time. The public availability of exploit code and the remote nature of the attack raise the overall risk, and the absence of a CISA KEV listing does not reduce the threat posture. Successful exploitation would allow an attacker to run any command on the router, potentially gaining persistence, exfiltrating data, or pivoting to adjacent devices.

Generated by OpenCVE AI on September 25, 2026 at 00:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest firmware patch that addresses OS command injection in /cgi-bin/dropbox.cgi, which mitigates weaknesses identified as CWE‑77 and CWE‑78.
  • If a patch cannot be deployed immediately, isolate the device by restricting the router’s management interface to trusted internal networks or a dedicated VLAN, preventing external hosts from reaching port 80/443.
  • As a temporary countermeasure, block or filter HTTP requests to /cgi-bin/dropbox.cgi on the router or through an external firewall, effectively disabling the vulnerable CGI handler.

Generated by OpenCVE AI on September 25, 2026 at 00:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
Title D-Link DNS-340L CGI dropbox.cgi os command injection
First Time appeared D-link
D-link dns-340l
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-340l
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-04T14:24:18.613Z

Reserved: 2026-09-03T14:24:33.078Z

Link: CVE-2026-85223

cve-icon Vulnrichment

Updated: 2026-09-04T14:23:58.497Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T22:18:24.080

Modified: 2026-09-04T15:17:36.387

Link: CVE-2026-85223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T01:00:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')