Description
A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely.
Problem types
Product status
Timeline
| 2026-05-10: | Advisory disclosed |
| 2026-05-10: | VulDB entry created |
| 2026-05-10: | VulDB entry last update |
Credits
ST4R (VulDB User)
References
vuldb.com/vuln/362570 (VDB-362570 | D-Link DNS-320 system_mgr.cgi cgi_merge_user os command injection)
vuldb.com/vuln/362570/cti (VDB-362570 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/810082 (Submit #810082 | D-Link Corporation DNS-320 ShareCenter NAS (Rev.A) Firmware 2.06B01 HOTFIX CWE-78: OS Command Injection)
github.com/...grapp_mgr Multiple CGI OS Command Injection.md
www.dlink.com/