Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-16332: D-Link DNS-320: Unrestricted File Upload via Malicious Data
CVE-2026-16332
Summary
An unknown function in the D-Link DNS-320's multi_uploadify.php file allows attackers to upload any file without restrictions. This can lead to unauthorized access to the device and potentially compromise its security. D-Link users should consider updating their firmware to the latest version to mitigate this risk.
Original title
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unre...
Original description
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
5.5
Vulnerability type
CWE-284
Improper Access Control
CWE-434
Unrestricted File Upload
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026