Dns 340l D Link Dns 340l

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in D Link Dns 340l.

By the Year

In 2026 there have been 8 vulnerabilities in D Link Dns 340l with an average score of 9.0 out of ten.

Year Vulnerabilities Average Score
2026 8 9.01

It may take a day or so for new Dns 340l vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent D Link Dns 340l Security Vulnerabilities

D-Link DNS-340L 1.01B04 Remote OS Command Injection via CGI Handler
CVE-2026-85223 9.4 - Critical - September 03, 2026

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

Shell injection

D-Link DNS340L 1.01B04 AddOn Center CGI OS Command Injection Remote
CVE-2026-85222 9.4 - Critical - September 03, 2026

A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Shell injection

D-Link DNS-340L/DNS-345 OS Command Injection via iscsi_mgr.cgi
CVE-2026-82692 9.4 - Critical - August 31, 2026

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Shell injection

OS Command Injection via usb_device CGI on D-Link DNS-32xL Series
CVE-2026-82691 9.4 - Critical - August 31, 2026

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Shell injection

D-Link DNS-327L/DNS-340L: os Command Injection via CGI Argument f_dev (remote)
CVE-2026-82690 9.4 - Critical - August 31, 2026

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Shell injection

D-Link DNS Router OS Command Injection via ISO Image Handler (CVE-2026-82689)
CVE-2026-82689 9.4 - Critical - August 31, 2026

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.

Shell injection

D-Link DNS-340L/345 OS command injection via Virtual Volume Handler before 1.05b04
CVE-2026-82688 9.4 - Critical - August 31, 2026

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Shell injection

D-Link DNS- series cmdinject in remote_backup.cgi
CVE-2026-16448 6.3 - Medium - July 21, 2026

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.

Command Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for D Link Dns 340l or by D Link? Click the Watch button to subscribe.

D Link
Vendor

subscribe