Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-16331: D-Link DNS-320 allows unauthorized file uploads

CVE-2026-16331 CVE-2026-16331
Summary

A security weakness in the D-Link DNS-320 allows hackers to upload any file they want without permission, potentially leading to system compromise or data theft. This vulnerability can be exploited remotely by an attacker, and a public exploit is available. To protect your device, we recommend checking for updates and applying any available patches.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
d-link dns-320 1.0.2
Original title
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler lea...
Original description
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
mitre CVSS3.1 7.3
Vulnerability type
CWE-434 Unrestricted File Upload
CWE-284 Improper Access Control
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026