D Link Dns 320
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in D Link Dns 320.
Known Exploited D Link Dns 320 Vulnerabilities
The following D Link Dns 320 vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| D-Link DNS-320 Command Injection Remote Code Execution Vulnerability |
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution. CVE-2020-25506 Exploit Probability: 100.0% |
November 3, 2021 |
The vulnerability CVE-2020-25506: D-Link DNS-320 Command Injection Remote Code Execution Vulnerability is in the top 1% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 7 vulnerabilities in D Link Dns 320 with an average score of 7.2 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 7 | 7.16 |
It may take a day or so for new Dns 320 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent D Link Dns 320 Security Vulnerabilities
D-Link DNS- series cmdinject in remote_backup.cgi
CVE-2026-16448
6.3 - Medium
- July 21, 2026
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
Command Injection
Unrestricted Upload via Filedata[] in D-Link DNS-320 1.0.2 (multi_uploadify.php)
CVE-2026-16447
7.3 - High
- July 21, 2026
A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Unrestricted File Upload
Unrestricted File Upload in D-Link DNS-320 1.0.2 via multi_uploadify.php
CVE-2026-16332
7.3 - High
- July 21, 2026
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Unrestricted File Upload
Unrestricted Upload in D-Link DNS-320 1.0.2 /save_ajax.php
CVE-2026-16331
7.3 - High
- July 21, 2026
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Unrestricted File Upload
D-Link DNS320 1.0.2: Unrestricted File Upload via uploadify.php
CVE-2026-16330
7.3 - High
- July 21, 2026
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Unrestricted File Upload
D-Link DNS-320 1.0.2 Unrestricted File Upload via uploadify.php
CVE-2026-16329
7.3 - High
- July 21, 2026
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
Unrestricted File Upload
D-Link DNS-320 1.0.2 Remote Unrestricted File Upload via /web/web_file/upload.php
CVE-2026-16327
7.3 - High
- July 20, 2026
A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Unrestricted File Upload
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for D Link Dns 320 or by D Link? Click the Watch button to subscribe.