<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-82692 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-82692/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 31 Aug 2026 12:00:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-82692/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in D-Link Virtual Volume Handler</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82688/</link><pubDate>Mon, 31 Aug 2026 12:00:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82688/</guid><description>D-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.</description><content:encoded><![CDATA[<p>CVE-2026-82688 identifies a critical OS command injection vulnerability in the Virtual Volume Handler component of D-Link DNS-340L and DNS-345 network storage devices, specifically affecting firmware versions 1.01B04, 1.03B06, 1.04.B02, and 1.05b04. The vulnerability manifests in the /cgi-bin/virtual_vol.cgi script, which fails to properly sanitize user-supplied input provided via the f_sharename, f_target, or f_name arguments. By injecting shell metacharacters into these parameters, an unauthenticated remote attacker can execute arbitrary system commands with the privileges of the web server. Public exploits are available for this vulnerability, significantly lowering the barrier for exploitation. Defenders should monitor web server logs for suspicious requests targeting the virtual_vol.cgi endpoint containing shell-specific syntax.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows remote attackers to gain unauthorized code execution on affected NAS hardware. Given these devices often function as central storage for organizational or personal data, impact includes full system compromise, data exfiltration, and potential lateral movement into the network where the device is hosted.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Immediate mitigation is required as this vulnerability is exploitable remotely and proof-of-concept code is public. Organizations utilizing these D-Link storage models should isolate the devices from the internet immediately if they cannot be updated, and monitor web server access logs for anomalous POST or GET requests to the /cgi-bin/virtual_vol.cgi endpoint containing command injection patterns.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>webserver</category><category>vulnerability</category><category>remote-code-execution</category><category>cve-2026-82692</category><category>storage-device</category></item></channel></rss>