CVE-2026-82689: D-Link DNS-320L/DNS-327L/DNS-340L/DNS-345 ISO Image isomount_mgr.cgi os command injection
A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomountmgr.cgi of the component ISO Image Handler. The manipulation of the argument upIsoRootPath results in os command injection. The attack can be executed remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Which systems should be prioritized for investigation?
D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 devices are identified as affected, specifically where the ISO Image Handler and its /cgi-bin/isomount_mgr.cgi endpoint are present. The affected versions are reported as up to 20260717.
What access does an attacker need to exploit this issue?
The attack can be executed remotely and requires low privileges. No user interaction is required, and exploitation targets the upIsoRootPath argument handled by the ISO Image Handler.
How serious is successful exploitation?
Successful exploitation can result in operating-system command injection, with high impact to confidentiality, integrity, and availability. The vulnerability is rated critical with a CVSS score of 9.9, and public exploit code is reported to be available.