CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability
A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.
What's new
- l2 added CVE-2026-16329 +3 Jul 21, 03:17 via nvd
- l2 added detection rule: Detects CVE-2026-16331 Exploitation - Unrestricted File Upload to D-Link DNS-320 Jul 21, 01:21 via nvd
- l2 added detection rule: Detects CVE-2026-16330 Exploitation - D-Link DNS-320 Unrestricted Upload Jul 21, 01:19 via nvd
- l2 added detection rule: Detect CVE-2026-16329 Exploitation - D-Link DNS-320 Unrestricted Upload Jul 21, 01:18 via nvd
A high-severity vulnerability, identified as CVE-2026-16327, exists in the D-Link DNS-320 network-attached storage (NAS) device, specifically in firmware version 1.0.2. This flaw resides within the /web/web_file/upload.php endpoint, where an attacker can manipulate the File argument to achieve unrestricted file upload. This allows remote, unauthenticated attackers to upload arbitrary files, such as web shells, to the device. Successful exploitation of this vulnerability can lead to remote code execution, giving adversaries full control over the D-Link DNS-320 device. The exploit for this vulnerability has been publicly disclosed, increasing the risk of widespread exploitation against unpatched systems. Defenders should prioritize patching and monitoring for exploitation attempts to mitigate potential compromise of these internet-facing devices.
Attack Chain
- A remote attacker crafts a malicious HTTP POST request targeting the
/web/web_file/upload.phpendpoint on a vulnerable D-Link DNS-320 device. - The request includes a specially manipulated
Fileargument designed to bypass file type or path restrictions. - The vulnerable D-Link device processes the request, failing to properly validate the uploaded file, leading to the storage of a malicious file (e.g., a web shell) in a publicly accessible directory.
- The attacker then makes a subsequent HTTP GET or POST request to the known location of the uploaded malicious file (the web shell).
- This access executes arbitrary commands or code on the D-Link DNS-320, achieving remote code execution.
- Successful exploitation grants the attacker persistent access and control over the network-attached storage device, potentially enabling further network compromise, data exfiltration, or denial-of-service.
Impact
Successful exploitation of CVE-2026-16327 leads to complete compromise of the affected D-Link DNS-320 device. Attackers can gain remote code execution, allowing them to steal sensitive data stored on the NAS, use the device as a pivot point for further attacks into the internal network, or disrupt device operations. Given that NAS devices often store critical business or personal data, the impact can include significant data breaches, loss of data integrity, and disruption of services. Public disclosure of the exploit code escalates the threat, making widespread targeting of unpatched devices highly probable.
Recommendation
- Patch CVE-2026-16327 on all D-Link DNS-320 1.0.2 devices immediately by updating to a secure firmware version provided by D-Link.
- Deploy the Sigma rule "Detects CVE-2026-16327 Exploitation - D-Link DNS-320 Unrestricted Upload" to your SIEM to detect attempted exploitation of the
/web/web_file/upload.phpendpoint. - Implement network segmentation to isolate D-Link DNS-320 devices from critical internal networks and restrict internet access to only necessary services.
- Review web server access logs for
/web/web_file/upload.phpfor any unauthorized POST requests, especially those with unusualcs-uri-querycontent or resulting in unexpected file types.
Detection coverage 4
Detects CVE-2026-16327 Exploitation - D-Link DNS-320 Unrestricted Upload
highDetects exploitation attempts against CVE-2026-16327, an unrestricted file upload vulnerability in D-Link DNS-320, by monitoring HTTP POST requests to the vulnerable /web/web_file/upload.php endpoint.
Detect CVE-2026-16329 Exploitation - D-Link DNS-320 Unrestricted Upload
highDetects exploitation attempts for CVE-2026-16329, an unrestricted file upload vulnerability in D-Link DNS-320. This rule specifically targets HTTP POST requests to the vulnerable /photo_center/php/uploadify.php endpoint with the 'Malicious Handler' argument, which is used for bypass file type restrictions.
Detects CVE-2026-16330 Exploitation - D-Link DNS-320 Unrestricted Upload
highDetects exploitation attempts for CVE-2026-16330, an unrestricted file upload vulnerability in D-Link DNS-320, by monitoring HTTP POST requests to the vulnerable uploadify.php endpoint with suspicious file extensions.
Detects CVE-2026-16331 Exploitation - Unrestricted File Upload to D-Link DNS-320
highDetects CVE-2026-16331 exploitation attempts by identifying suspicious HTTP POST requests to the `/web/function/save_ajax.php` endpoint containing the 'Malicious Handler' argument, indicative of an unrestricted file upload attempt.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
1
url
| Type | Value |
|---|---|
| url | https://ucn9h68n9289.feishu.cn/docx/EbAkdl1v8oC3Q3xAEJLcZFcZnMY?from=from_copylink |