Skip to content
Threat Feed

Tag

Nas

5 briefs RSS
critical advisory

Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic

Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.

DiskStation Manager +7 vulnerability critical remote-code-execution file-read-write dsm file-access synology cve +4
1t 6c
critical advisory

OS Command Injection in D-Link Virtual Volume Handler

D-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.

DNS-340L +4 webserver vulnerability remote-code-execution cve-2026-82692 storage-device cve-2026-85222 command-injection nas +1
3r 3t 1c updated
critical threat

Unauthenticated Remote Code Execution in D-Link NAS Devices

Multiple D-Link NAS devices are vulnerable to unauthenticated OS command injection via the account_mgr.cgi script, allowing remote attackers to execute arbitrary commands with root privileges.

exploited DNS-320 +3 remote-code-execution nas hardware vulnerability
1r 1t 1c
high advisory

CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability

A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.

DNS-320 1.0.2 web-vulnerability remote-code-execution file-upload d-link unrestricted-file-upload nas vulnerability unrestricted-upload +2
4r 4t 2i updated
critical advisory

EFM ipTIME NAS1dual Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability exists in EFM ipTIME NAS1dual 1.5.24, affecting the get_csrf_whites function in /cgi/advanced/misc_main.cgi, exploitable remotely, and leading to potential arbitrary code execution.

ipTIME NAS1dual 1.5.24 stack-based-buffer-overflow cve-2026-7834 iptime nas webserver
2r 1t 1c