Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-82692: D-Link DNS-340L/345 allows remote command execution

CVE-2026-82692 · published 3 days ago
Summary

The web management interface on D-Link DNS-340L and DNS-345 devices can be tricked into running operating system commands by sending specially crafted input. This can be done from anywhere on the network, giving an attacker the ability to control the device. Apply the latest firmware update from D-Link as soon as possible to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dns-340l 20260717
d-link dns-345 20260717
Original advisory text
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/pa...
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Severity
8.6 High
CVSS 2.0: 9.0 (NVD)
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 8.6 (NVD)
Exploitation
EPSS 2%
Type
CWE-77Command Injection
CWE-78OS Command Injection
Timeline
Published31 Aug 2026
Updated2 Sep 2026
First seen31 Aug 2026
Sources
CVE-2026-82692 · MITRE
Monitor software like this
Free during beta