Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-16331: D-Link DNS-320 allows unauthorized file uploads
CVE-2026-16331
CVE-2026-16331
Summary
A security weakness in the D-Link DNS-320 allows hackers to upload any file they want without permission, potentially leading to system compromise or data theft. This vulnerability can be exploited remotely by an attacker, and a public exploit is available. To protect your device, we recommend checking for updates and applying any available patches.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dns-320 | 1.0.2 |
Original title
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler lea...
Original description
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
mitre CVSS3.1
7.3
Vulnerability type
CWE-434
Unrestricted File Upload
CWE-284
Improper Access Control
- https://vuldb.com/vuln/380697 vdb-entry technical-description
- https://vuldb.com/vuln/380697/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-16331 third-party-advisory
- https://vuldb.com/submit/858464 third-party-advisory
- https://ucn9h68n9289.feishu.cn/docx/UZ6id3F1Joqlpxxn3NFcL8r7nHb?from=from_copyli... exploit
- https://www.dlink.com/ product
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026