Impact
The flaw is in the D-Link DNS‑340L router’s CGI handler /cgi-bin/dropbox.cgi. A crafted request that modifies the callback_url or sync_interval parameters causes an OS command injection, allowing an attacker to execute arbitrary commands. The vulnerability is exploitable remotely and public exploit code is available.
Affected Systems
D-Link DNS‑340L routers running firmware 1.01B04 are affected. No other products or versions are listed.
Risk and Exploitability
The CVSS score of 9.4 marks this as critical. Although a public exploit exists, the EPSS score is not provided; nevertheless the lack of a KEV listing does not reduce the threat. The attack can be launched from any machine that can reach the router’s web interface. Successful exploitation would give the attacker full control over the device’s operating system.
OpenCVE Enrichment