{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dns-340l--20260717/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-82690"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DNS-327L (\u003c= 20260717)","DNS-340L (\u003c= 20260717)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","network-storage"],"_cs_type":"threat","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eA critical security vulnerability has been identified in D-Link DNS-327L and DNS-340L network-attached storage (NAS) devices. The flaw resides in the /cgi-bin/ve_mgr.cgi script, which fails to properly sanitize user-supplied input. By injecting malicious payloads into the f_dev parameter, an unauthenticated attacker can achieve remote code execution (RCE) with the privileges of the web server. This vulnerability is remotely exploitable and proof-of-concept exploit code has been publicly released, increasing the risk of active exploitation. Organizations using these specific NAS models are at high risk of unauthorized system access and potential data exfiltration or device compromise. The vulnerability affects all firmware versions up to and including the 20260717 release.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows for full, unauthenticated remote command execution on affected D-Link NAS devices. This could lead to a complete compromise of the device, unauthorized access to stored data, lateral movement into internal networks, or the deployment of persistent malware. Given the public availability of exploit code, the likelihood of targeted attacks against exposed storage appliances is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediate mitigation is required for all internet-facing D-Link DNS-327L and DNS-340L devices.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure that NAS devices are not exposed directly to the internet; place them behind a firewall or VPN.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous HTTP requests targeting /cgi-bin/ve_mgr.cgi, specifically looking for shell metacharacters in the f_dev argument.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized outbound network traffic originating from these storage devices, which may indicate post-exploitation activity.\u003c/li\u003e\n\u003cli\u003eApply the latest firmware patches provided by D-Link if a version newer than 20260717 is available.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T13:58:19Z","date_published":"2026-08-31T13:58:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dlink-command-injection/","summary":"A critical command injection vulnerability in D-Link DNS-327L and DNS-340L devices allows unauthenticated remote code execution via manipulation of the f_dev parameter.","title":"Remote Command Injection in D-Link NAS Devices","url":"https://feed.craftedsignal.io/briefs/2026-08-dlink-command-injection/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-82688"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DNS-340L (1.01B04, 1.03B06, 1.04.B02, 1.05b04)","DNS-345 (1.01B04, 1.03B06, 1.04.B02, 1.05b04)","DNS-340L (\u003c= 20260717)","DNS-345 (\u003c= 20260717)"],"_cs_severities":["critical"],"_cs_tags":["webserver","vulnerability","remote-code-execution","cve-2026-82692","storage-device"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eCVE-2026-82688 identifies a critical OS command injection vulnerability in the Virtual Volume Handler component of D-Link DNS-340L and DNS-345 network storage devices, specifically affecting firmware versions 1.01B04, 1.03B06, 1.04.B02, and 1.05b04. The vulnerability manifests in the /cgi-bin/virtual_vol.cgi script, which fails to properly sanitize user-supplied input provided via the f_sharename, f_target, or f_name arguments. By injecting shell metacharacters into these parameters, an unauthenticated remote attacker can execute arbitrary system commands with the privileges of the web server. Public exploits are available for this vulnerability, significantly lowering the barrier for exploitation. Defenders should monitor web server logs for suspicious requests targeting the virtual_vol.cgi endpoint containing shell-specific syntax.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to gain unauthorized code execution on affected NAS hardware. Given these devices often function as central storage for organizational or personal data, impact includes full system compromise, data exfiltration, and potential lateral movement into the network where the device is hosted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediate mitigation is required as this vulnerability is exploitable remotely and proof-of-concept code is public. Organizations utilizing these D-Link storage models should isolate the devices from the internet immediately if they cannot be updated, and monitor web server access logs for anomalous POST or GET requests to the /cgi-bin/virtual_vol.cgi endpoint containing command injection patterns.\u003c/p\u003e\n","date_modified":"2026-08-31T13:58:34Z","date_published":"2026-08-31T12:00:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82688/","summary":"D-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.","title":"OS Command Injection in D-Link Virtual Volume Handler","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82688/"}],"language":"en","title":"CraftedSignal Threat Feed - DNS-340L (\u003c= 20260717)","version":"https://jsonfeed.org/version/1.1"}