<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>DNS-320 1.0.2 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dns-320-1.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 21 Jul 2026 00:20:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dns-320-1.0.2/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16327-d-link-unrestricted-upload/</link><pubDate>Tue, 21 Jul 2026 00:20:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16327-d-link-unrestricted-upload/</guid><description>A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.</description><content:encoded><![CDATA[<p>A high-severity vulnerability, identified as CVE-2026-16327, exists in the D-Link DNS-320 network-attached storage (NAS) device, specifically in firmware version 1.0.2. This flaw resides within the <code>/web/web_file/upload.php</code> endpoint, where an attacker can manipulate the <code>File</code> argument to achieve unrestricted file upload. This allows remote, unauthenticated attackers to upload arbitrary files, such as web shells, to the device. Successful exploitation of this vulnerability can lead to remote code execution, giving adversaries full control over the D-Link DNS-320 device. The exploit for this vulnerability has been publicly disclosed, increasing the risk of widespread exploitation against unpatched systems. Defenders should prioritize patching and monitoring for exploitation attempts to mitigate potential compromise of these internet-facing devices.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>A remote attacker crafts a malicious HTTP POST request targeting the <code>/web/web_file/upload.php</code> endpoint on a vulnerable D-Link DNS-320 device.</li>
<li>The request includes a specially manipulated <code>File</code> argument designed to bypass file type or path restrictions.</li>
<li>The vulnerable D-Link device processes the request, failing to properly validate the uploaded file, leading to the storage of a malicious file (e.g., a web shell) in a publicly accessible directory.</li>
<li>The attacker then makes a subsequent HTTP GET or POST request to the known location of the uploaded malicious file (the web shell).</li>
<li>This access executes arbitrary commands or code on the D-Link DNS-320, achieving remote code execution.</li>
<li>Successful exploitation grants the attacker persistent access and control over the network-attached storage device, potentially enabling further network compromise, data exfiltration, or denial-of-service.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-16327 leads to complete compromise of the affected D-Link DNS-320 device. Attackers can gain remote code execution, allowing them to steal sensitive data stored on the NAS, use the device as a pivot point for further attacks into the internal network, or disrupt device operations. Given that NAS devices often store critical business or personal data, the impact can include significant data breaches, loss of data integrity, and disruption of services. Public disclosure of the exploit code escalates the threat, making widespread targeting of unpatched devices highly probable.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-16327 on all D-Link DNS-320 1.0.2 devices immediately by updating to a secure firmware version provided by D-Link.</li>
<li>Deploy the Sigma rule &quot;Detects CVE-2026-16327 Exploitation - D-Link DNS-320 Unrestricted Upload&quot; to your SIEM to detect attempted exploitation of the <code>/web/web_file/upload.php</code> endpoint.</li>
<li>Implement network segmentation to isolate D-Link DNS-320 devices from critical internal networks and restrict internet access to only necessary services.</li>
<li>Review web server access logs for <code>/web/web_file/upload.php</code> for any unauthorized POST requests, especially those with unusual <code>cs-uri-query</code> content or resulting in unexpected file types.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>remote-code-execution</category><category>file-upload</category><category>d-link</category><category>unrestricted-file-upload</category><category>nas</category><category>vulnerability</category><category>unrestricted-upload</category><category>webserver</category><category>cve</category></item></channel></rss>