D-Link DNS-340L 和 DNS-345 设备(截至固件版本 20260717)中存在一个漏洞。该漏洞影响 文件的未知部分。当攻击者对 、 、 或 参数进行特定操纵时,会触发操作系统命令注入。该攻击可通过远程发起,且利用代码已公开,可能被用于实际攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82689 | 9.9 CRITICAL | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection |
| CVE-2026-82691 | 9.1 CRITICAL | D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 CGI usb_device.cgi os command injection |
| CVE-2026-82690 | 9.1 CRITICAL | D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection |
| CVE-2026-82688 | 9.1 CRITICAL | D-Link DNS-340L/DNS-345 Virtual Volume virtual_vol.cgi os command injection |
| CVE-2026-82680 | 8.8 HIGH | D-Link DSM-G600 Multipart load_file.cgi out-of-bounds write |
No comments yet