Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-16329: D-Link DNS-320 allows malicious file uploads
CVE-2026-16329
CVE-2026-16329
Summary
A security issue affects the D-Link DNS-320, allowing hackers to upload any file they want without restrictions. This could lead to the DNS-320 being compromised or used to spread malware. To stay safe, update the DNS-320 to the latest version or consider replacing it with a newer model.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dns-320 | 1.0.2 |
Original title
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unre...
Original description
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
mitre CVSS3.1
7.3
Vulnerability type
CWE-434
Unrestricted File Upload
CWE-284
Improper Access Control
- https://vuldb.com/vuln/380694 vdb-entry technical-description
- https://vuldb.com/vuln/380694/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-16329 third-party-advisory
- https://vuldb.com/submit/858462 third-party-advisory
- https://ucn9h68n9289.feishu.cn/docx/MBHDdPBz4oUXa9xCdujchmPZneg?from=from_copyli... exploit
- https://www.dlink.com/ product
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026