← All Advisories

D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 ISO Image Mount Handler Passes Mount Arguments Unsanitized to the Shell, Allowing Low-Privileged Attackers to Execute Remote Commands

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-82689

Key Details

CVECVE-2026-82689
CVSS Score / Version9.9 (Critical) / CVSS v3.1
Updated2026-08-31
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection'))

What to Know

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-82689
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-82689