{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-85224/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:dlink:dns-320:2.06b01:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-85224"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DNS-320 ShareCenter (2.06B01)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-85224","nas","command-injection","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DNS-320 ShareCenter version 2.06B01 is susceptible to an unauthenticated remote OS command injection vulnerability. The flaw exists within the File Sharing component, specifically affecting the /cgi/file_sharing.cgi script. An attacker can trigger this vulnerability by sending a maliciously crafted request to the device, manipulating the 'fileurl' argument. Because this vulnerability allows for arbitrary command execution on the underlying operating system, it poses a significant risk to the integrity and confidentiality of the affected device. Publicly disclosed exploit code currently exists for this CVE, increasing the likelihood of exploitation. Defensive teams should prioritize remediation, as this vulnerability provides a direct pathway for unauthenticated actors to gain control of vulnerable network-attached storage (NAS) devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to execute arbitrary commands with the privileges of the web server on the D-Link DNS-320 ShareCenter device. This can lead to complete system compromise, unauthorized data access, persistence establishment, or the device's inclusion in botnet activity. Given the nature of NAS devices, potential impacts include the exfiltration or encryption of stored files and the use of the device as a pivot point within the local network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eIdentify all internet-facing D-Link DNS-320 ShareCenter devices within your environment using network scanning or asset inventory tools.\u003c/li\u003e\n\u003cli\u003eRestrict management interface access to trusted administrative networks only; ensure these devices are not exposed to the public internet.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous HTTP requests targeting /cgi/file_sharing.cgi containing shell metacharacters in the fileurl parameter.\u003c/li\u003e\n\u003cli\u003eEvaluate the necessity of continuing the use of this legacy hardware, as specific security patches for version 2.06B01 may be unavailable; segment affected devices from sensitive internal networks.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T23:23:54Z","date_published":"2026-09-03T23:23:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/","summary":"D-Link DNS-320 ShareCenter version 2.06B01 contains a remote OS command injection vulnerability in the File Sharing component, allowing unauthenticated attackers to execute arbitrary system commands.","title":"Remote OS Command Injection in D-Link DNS-320 ShareCenter","url":"https://feed.craftedsignal.io/briefs/2026-09-dlink-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-85224","version":"https://jsonfeed.org/version/1.1"}