Remote OS Command Injection in D-Link DNS-320 ShareCenter
D-Link DNS-320 ShareCenter version 2.06B01 contains a remote OS command injection vulnerability in the File Sharing component, allowing unauthenticated attackers to execute arbitrary system commands.
CVE search metadata
CVE search record: CVE-2026-85224. Severity: critical. CVSS: 9.1. KEV: no. Product: DNS-320 ShareCenter (2.06B01). Brief: Remote OS Command Injection in D-Link DNS-320 ShareCenter. Brief link: https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/
D-Link DNS-320 ShareCenter version 2.06B01 is susceptible to an unauthenticated remote OS command injection vulnerability. The flaw exists within the File Sharing component, specifically affecting the /cgi/file_sharing.cgi script. An attacker can trigger this vulnerability by sending a maliciously crafted request to the device, manipulating the 'fileurl' argument. Because this vulnerability allows for arbitrary command execution on the underlying operating system, it poses a significant risk to the integrity and confidentiality of the affected device. Publicly disclosed exploit code currently exists for this CVE, increasing the likelihood of exploitation. Defensive teams should prioritize remediation, as this vulnerability provides a direct pathway for unauthenticated actors to gain control of vulnerable network-attached storage (NAS) devices.
Impact
Successful exploitation of this vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with the privileges of the web server on the D-Link DNS-320 ShareCenter device. This can lead to complete system compromise, unauthorized data access, persistence establishment, or the device's inclusion in botnet activity. Given the nature of NAS devices, potential impacts include the exfiltration or encryption of stored files and the use of the device as a pivot point within the local network.
Recommendation
- Identify all internet-facing D-Link DNS-320 ShareCenter devices within your environment using network scanning or asset inventory tools.
- Restrict management interface access to trusted administrative networks only; ensure these devices are not exposed to the public internet.
- Monitor web server access logs for anomalous HTTP requests targeting /cgi/file_sharing.cgi containing shell metacharacters in the fileurl parameter.
- Evaluate the necessity of continuing the use of this legacy hardware, as specific security patches for version 2.06B01 may be unavailable; segment affected devices from sensitive internal networks.
Immediate actions
Audit network perimeter for D-Link DNS-320 devices reachable from the internet.
Mitigations
Remove public-facing access to the web management interface for affected D-Link devices.
CVE-2026-85224
Detection coverage 1
Detects CVE-2026-85224 Exploitation - Remote OS Command Injection
criticalDetects attempts to exploit CVE-2026-85224 by identifying shell metacharacters within the fileurl argument of the /cgi/file_sharing.cgi endpoint.
Detection queries are available on the platform. Get full rules →