D-Link DNS-320是中国友讯(D-Link)公司的一款NAS(网络附属存储)设备。 D-Link DNS-320 2.06B01版本存在命令注入漏洞,该漏洞源于文件/cgi-bin/network_mgr.cgi中函数cgi_speed/cgi_dhcpd_lease/cgi_ddns/cgi_set_ip/cgi_upnp_del/cgi_dhcpd/cgi_upnp_add/cgi_upnp_edit可能导致OS命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8260 | 8.8 HIGH | D-Link DCS-935L HNAP Service hnap_service SetDeviceSettings buffer overflow |
| CVE-2026-8346 | 6.3 MEDIUM | D-Link DIR-816 portForward command injection |
| CVE-2026-8345 | 6.3 MEDIUM | D-Link DIR-816 singlePortForward sub_445E7C command injection |
| CVE-2026-8344 | 6.3 MEDIUM | D-Link DIR-816 formDMZ.cgi sub_445E7C command injection |
| CVE-2026-8273 | 4.7 MEDIUM | D-Link DNS-320 system_mgr.cgi cgi_merge_user os command injection |
| CVE-2026-8272 | 4.7 MEDIUM | D-Link DNS-320 webfile_mgr.cgi chown os command injection |
No comments yet