Skip to content
Threat Feed
critical advisory

Remote OS Command Injection in D-Link DNS-320 ShareCenter

D-Link DNS-320 ShareCenter version 2.06B01 contains a remote OS command injection vulnerability in the File Sharing component, allowing unauthenticated attackers to execute arbitrary system commands.

CVE search metadata

CVE search record: CVE-2026-85224. Severity: critical. CVSS: 9.1. KEV: no. Product: DNS-320 ShareCenter (2.06B01). Brief: Remote OS Command Injection in D-Link DNS-320 ShareCenter. Brief link: https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/

D-Link DNS-320 ShareCenter version 2.06B01 is susceptible to an unauthenticated remote OS command injection vulnerability. The flaw exists within the File Sharing component, specifically affecting the /cgi/file_sharing.cgi script. An attacker can trigger this vulnerability by sending a maliciously crafted request to the device, manipulating the 'fileurl' argument. Because this vulnerability allows for arbitrary command execution on the underlying operating system, it poses a significant risk to the integrity and confidentiality of the affected device. Publicly disclosed exploit code currently exists for this CVE, increasing the likelihood of exploitation. Defensive teams should prioritize remediation, as this vulnerability provides a direct pathway for unauthenticated actors to gain control of vulnerable network-attached storage (NAS) devices.

Impact

Successful exploitation of this vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with the privileges of the web server on the D-Link DNS-320 ShareCenter device. This can lead to complete system compromise, unauthorized data access, persistence establishment, or the device's inclusion in botnet activity. Given the nature of NAS devices, potential impacts include the exfiltration or encryption of stored files and the use of the device as a pivot point within the local network.

Recommendation

  1. Identify all internet-facing D-Link DNS-320 ShareCenter devices within your environment using network scanning or asset inventory tools.
  2. Restrict management interface access to trusted administrative networks only; ensure these devices are not exposed to the public internet.
  3. Monitor web server access logs for anomalous HTTP requests targeting /cgi/file_sharing.cgi containing shell metacharacters in the fileurl parameter.
  4. Evaluate the necessity of continuing the use of this legacy hardware, as specific security patches for version 2.06B01 may be unavailable; segment affected devices from sensitive internal networks.

Immediate actions

Audit network perimeter for D-Link DNS-320 devices reachable from the internet.

SOC 24h

Mitigations

Remove public-facing access to the web management interface for affected D-Link devices.

immediate IT Operations

CVE-2026-85224

Detection coverage 1

Detects CVE-2026-85224 Exploitation - Remote OS Command Injection

critical

Detects attempts to exploit CVE-2026-85224 by identifying shell metacharacters within the fileurl argument of the /cgi/file_sharing.cgi endpoint.

sigma tactics: execution, initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →