{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/dns-320-1.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DNS-320 1.0.2"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","remote-code-execution","file-upload","d-link","unrestricted-file-upload","nas","vulnerability","unrestricted-upload","webserver","cve"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eA high-severity vulnerability, identified as CVE-2026-16327, exists in the D-Link DNS-320 network-attached storage (NAS) device, specifically in firmware version 1.0.2. This flaw resides within the \u003ccode\u003e/web/web_file/upload.php\u003c/code\u003e endpoint, where an attacker can manipulate the \u003ccode\u003eFile\u003c/code\u003e argument to achieve unrestricted file upload. This allows remote, unauthenticated attackers to upload arbitrary files, such as web shells, to the device. Successful exploitation of this vulnerability can lead to remote code execution, giving adversaries full control over the D-Link DNS-320 device. The exploit for this vulnerability has been publicly disclosed, increasing the risk of widespread exploitation against unpatched systems. Defenders should prioritize patching and monitoring for exploitation attempts to mitigate potential compromise of these internet-facing devices.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA remote attacker crafts a malicious HTTP POST request targeting the \u003ccode\u003e/web/web_file/upload.php\u003c/code\u003e endpoint on a vulnerable D-Link DNS-320 device.\u003c/li\u003e\n\u003cli\u003eThe request includes a specially manipulated \u003ccode\u003eFile\u003c/code\u003e argument designed to bypass file type or path restrictions.\u003c/li\u003e\n\u003cli\u003eThe vulnerable D-Link device processes the request, failing to properly validate the uploaded file, leading to the storage of a malicious file (e.g., a web shell) in a publicly accessible directory.\u003c/li\u003e\n\u003cli\u003eThe attacker then makes a subsequent HTTP GET or POST request to the known location of the uploaded malicious file (the web shell).\u003c/li\u003e\n\u003cli\u003eThis access executes arbitrary commands or code on the D-Link DNS-320, achieving remote code execution.\u003c/li\u003e\n\u003cli\u003eSuccessful exploitation grants the attacker persistent access and control over the network-attached storage device, potentially enabling further network compromise, data exfiltration, or denial-of-service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-16327 leads to complete compromise of the affected D-Link DNS-320 device. Attackers can gain remote code execution, allowing them to steal sensitive data stored on the NAS, use the device as a pivot point for further attacks into the internal network, or disrupt device operations. Given that NAS devices often store critical business or personal data, the impact can include significant data breaches, loss of data integrity, and disruption of services. Public disclosure of the exploit code escalates the threat, making widespread targeting of unpatched devices highly probable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-16327 on all D-Link DNS-320 1.0.2 devices immediately by updating to a secure firmware version provided by D-Link.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-16327 Exploitation - D-Link DNS-320 Unrestricted Upload\u0026quot; to your SIEM to detect attempted exploitation of the \u003ccode\u003e/web/web_file/upload.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate D-Link DNS-320 devices from critical internal networks and restrict internet access to only necessary services.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for \u003ccode\u003e/web/web_file/upload.php\u003c/code\u003e for any unauthorized POST requests, especially those with unusual \u003ccode\u003ecs-uri-query\u003c/code\u003e content or resulting in unexpected file types.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-21T14:18:04Z","date_published":"2026-07-21T00:20:14Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16327-d-link-unrestricted-upload/","summary":"A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.","title":"CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16327-d-link-unrestricted-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - DNS-320 1.0.2","version":"https://jsonfeed.org/version/1.1"}