A publicly disclosed command injection flaw in the Virtual Volume Handler of D-Link DNS-340L and DNS-345 network storage devices could allow remote attackers to execute operating system commands, and carries a CVSS 3.1 base score of 9.1 (Critical).
What Is It
CVE-2026-82688 is an OS command injection vulnerability (CWE-77, CWE-78) affecting D-Link DNS-340L and DNS-345 storage devices. The flaw resides in an unknown function of the file /cgi-bin/virtual_vol.cgi, part of the Virtual Volume Handler component. Manipulation of the f_sharename, f_target, or f_name arguments is reported to lead to command injection. Remote exploitation is possible, and per the NVD record the exploit has been disclosed publicly and may be used.
The CVE was published on 2026-08-31 by VulDB ([email protected]) and currently sits in "Received" status at NVD.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. The changed scope is what drives the 9.1 rating: it indicates the scorer assessed that successful injection would reach beyond the vulnerable component itself. High privileges are required, which is the primary mitigating factor.
CVSS 4.0 scores the issue at 8.5 (High) with an exploit maturity of PROOF_OF_CONCEPT. That rating indicates proof-of-concept exploit material is publicly available, which can shorten the window between publication and opportunistic use, particularly for internet-exposed NAS appliances.
CVE-2026-82688 does not appear in CISA's Known Exploited Vulnerabilities catalog as of 2026-08-31, so active exploitation has not been confirmed by that source. Readers should check the catalog directly, since KEV entries are added as evidence emerges.
What's Vulnerable
- D-Link DNS-340L: versions 1.01B04, 1.03B06, 1.04.B02, 1.05b04 (Virtual Volume Handler)
- D-Link DNS-345: versions 1.01B04, 1.03B06, 1.04.B02, 1.05b04 (Virtual Volume Handler)
Affected CPEs: cpe:2.3:h:d-link:dns-340l and cpe:2.3:h:d-link:dns-345.
Patch Status
Neither the NVD record nor the VulDB entries listed below reference a vendor advisory, fixed version, or remediation guidance, and because the CVE is absent from CISA's KEV catalog as of 2026-08-31 there is no associated required action or due date. The only vendor reference carried in the NVD record is D-Link's main website. Both models are legacy NAS hardware; operators should treat patch availability as unconfirmed and verify current support and remediation status directly with the vendor.
Sources
- NVD, CVE-2026-82688: https://nvd.nist.gov/vuln/detail/CVE-2026-82688
- VulDB, CVE-2026-82688: https://vuldb.com/cve/CVE-2026-82688
- VulDB, Vulnerability 397176: https://vuldb.com/vuln/397176
- VulDB, CTI details: https://vuldb.com/vuln/397176/cti
- VulDB, Submission 894190: https://vuldb.com/submit/894190
- Researcher disclosure write-up (GitHub): https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-001-vulndb.md
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- D-Link: https://www.dlink.com/