Description
A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Problem types
Product status
Timeline
| 2026-05-10: | Advisory disclosed |
| 2026-05-10: | VulDB entry created |
| 2026-05-10: | VulDB entry last update |
Credits
ST4R (VulDB User)
References
vuldb.com/vuln/362569 (VDB-362569 | D-Link DNS-320 webfile_mgr.cgi chown os command injection)
vuldb.com/vuln/362569/cti (VDB-362569 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/810079 (Submit #810079 | D-Link Corporation DNS-320 ShareCenter NAS (Rev.A) Firmware 2.06B01 HOTFIX CWE-78: OS Command Injection)
github.com/...le OS Command Injection via File Operations.md
www.dlink.com/