Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-16327: D-Link DNS-320: Unrestricted File Upload via Remote Attack

CVE-2026-16327 CVE-2026-16327
Summary

A vulnerability in the D-Link DNS-320 allows attackers to upload unauthorized files remotely. This could potentially allow hackers to install malicious software on the device. To mitigate this risk, update the device to the latest firmware version or consider replacing it if a fix is not available.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
d-link dns-320 1.0.2
Original title
D-Link DNS-320 upload.php unrestricted upload
Original description
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd CVSS2.0 7.5
nvd CVSS3.1 7.3
nvd CVSS4.0 5.5
Vulnerability type
CWE-284 Improper Access Control
CWE-434 Unrestricted File Upload
Published: 20 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026