Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-16327: D-Link DNS-320: Unrestricted File Upload via Remote Attack
CVE-2026-16327
CVE-2026-16327
Summary
A vulnerability in the D-Link DNS-320 allows attackers to upload unauthorized files remotely. This could potentially allow hackers to install malicious software on the device. To mitigate this risk, update the device to the latest firmware version or consider replacing it if a fix is not available.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dns-320 | 1.0.2 |
Original title
D-Link DNS-320 upload.php unrestricted upload
Original description
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
5.5
Vulnerability type
CWE-284
Improper Access Control
CWE-434
Unrestricted File Upload
Published: 20 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026