CVE-2026-82690: D-Link DNS-327L/DNS-340L ve_mgr.cgi os command injection
Published Aug 31, 2026
·Updated
A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/vemgr.cgi. This manipulation of the argument fdev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
2 affected components
D-Link DNS-327L<=20260717
D-Link DNS-340L<=20260717
Event History
Aug 31, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are affected?
D-Link DNS-327L and DNS-340L devices are affected, including versions up to 20260717.
2
What access does an attacker need to exploit this issue?
The attack can be performed remotely and requires manipulation of the f_dev argument handled by /cgi-bin/ve_mgr.cgi. The provided data does not specify any authentication requirement.
3
Is exploitation likely to be practical?
An exploit has been published and may be used. The issue is rated critical with network attack vector and low attack complexity.