Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-82689: D-Link NAS devices allow remote command execution

CVE-2026-82689 · published 3 days ago
Summary

The D-Link DNS‑320L, DNS‑327L, DNS‑340L and DNS‑345 storage units let an attacker send specially crafted data to a web page (isomount_mgr.cgi) and cause the device to run arbitrary commands. This can be done over the network without needing physical access, and the technique is already publicly known. Update the device to the latest firmware or disable the affected web feature until a fix is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dns-320l 20260717
d-link dns-327l 20260717
d-link dns-340l 20260717
d-link dns-345 20260717
Original advisory text
A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Hand...
A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82689 · MITRE
Monitor software like this
Free during beta