Impact
A flaw in the D‑Link DNS‑320 ShareCenter 2.06B01 device’s File Sharing component allows an attacker to manipulate the fileurl parameter in the /cgi/file_sharing.cgi script. The parameter is not sanitized, so an attacker can inject arbitrary OS commands that the router executes with elevated privileges. This leads to complete compromise of the device’s operating system. The vulnerability is described as an OS command injection (CWE-77, CWE-78) and can be triggered remotely from outside the local network.
Affected Systems
The affected device is the D‑Link DNS‑320 ShareCenter running firmware version 2.06B01. The vulnerability resides in the file_sharing.cgi component of the File Sharing service on this router.
Risk and Exploitability
The CVSS score is 9.4, indicating critical severity, and the EPSS score is not available but the exploit is publicly disclosed and can be launched remotely. The vulnerability is not yet listed in the CISA KEV catalog, yet the combination of remote attack vector, high CVSS, and public availability of the exploit creates a high risk of exploitation.
OpenCVE Enrichment