Description
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-03
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the D‑Link DNS‑320 ShareCenter 2.06B01 device’s File Sharing component allows an attacker to manipulate the fileurl parameter in the /cgi/file_sharing.cgi script. The parameter is not sanitized, so an attacker can inject arbitrary OS commands that the router executes with elevated privileges. This leads to complete compromise of the device’s operating system. The vulnerability is described as an OS command injection (CWE-77, CWE-78) and can be triggered remotely from outside the local network.

Affected Systems

The affected device is the D‑Link DNS‑320 ShareCenter running firmware version 2.06B01. The vulnerability resides in the file_sharing.cgi component of the File Sharing service on this router.

Risk and Exploitability

The CVSS score is 9.4, indicating critical severity, and the EPSS score is not available but the exploit is publicly disclosed and can be launched remotely. The vulnerability is not yet listed in the CISA KEV catalog, yet the combination of remote attack vector, high CVSS, and public availability of the exploit creates a high risk of exploitation.

Generated by OpenCVE AI on September 3, 2026 at 23:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that addresses the command‑injection flaw on the D‑Link DNS‑320 ShareCenter.
  • If a firmware upgrade is not immediately possible, block or strictly limit remote access to the /cgi/file_sharing.cgi endpoint or disable the File Sharing feature through the router’s configuration settings.
  • Enable detailed logging for HTTP requests to the device and monitor for abnormal fileurl parameters or other suspicious activity, and implement alerts for such events.

Generated by OpenCVE AI on September 3, 2026 at 23:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection
First Time appeared D-link
D-link dns-320 Sharecenter
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-320_sharecenter:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-320 Sharecenter
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


Subscriptions

D-link Dns-320 Sharecenter
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-03T21:45:08.564Z

Reserved: 2026-09-03T14:31:34.496Z

Link: CVE-2026-85224

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-03T22:18:24.260

Modified: 2026-09-03T22:18:24.260

Link: CVE-2026-85224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T23:45:04Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')