CVE-2026-85224: D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/filesharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to remote exploitation?
D-Link DNS-320 ShareCenter devices running version 2.06B01 are identified as affected. The vulnerable File Sharing CGI endpoint can be targeted remotely.
What does an attacker need to exploit this issue?
An attacker needs the ability to send a crafted request that manipulates the fileurl argument handled by /cgi/file_sharing.cgi. No user interaction is indicated, but the supplied data does not establish whether authentication is required.
How serious is successful exploitation?
Successful exploitation can result in OS command injection with high impacts to confidentiality, integrity, and availability, including effects beyond the vulnerable security authority. Public exploit disclosure is reported.