A publicly disclosed command injection flaw in the iSCSI management CGI of D-Link DNS-340L and DNS-345 network storage devices reportedly allows a remote, low-privileged attacker to execute arbitrary OS commands.
What Is It
CVE-2026-82692 is an OS command injection vulnerability (CWE-77, CWE-78) affecting an unknown component in the file /cgi-bin/iscsi_mgr.cgi on D-Link DNS-340L and DNS-345 devices. According to the VulDB-sourced record, manipulating the alias, username, password, or volume_location arguments is said to result in command injection; the underlying code path has not been independently verified here, and the affected component is described only in general terms in the source material. The attack is described as remotely initiable, and per the NVD record, the exploit has been made public and could be used.
The vulnerability was published on 2026-08-31 by VulDB ([email protected]) and currently carries a vulnerability status of "Received." That status means the record has not yet completed NVD analysis, so the technical details above rest on the reporting party's claims rather than on confirmed downstream review.
Why It Matters
The CVSS v3.1 base score is 9.9 (CRITICAL): network attack vector, low attack complexity, low privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. Note that the vector string carried in the source record is malformed: it is prefixed CVSS:4.0/ while using v3.1-only metrics (notably S:C, scope, which does not exist in v4.0), so the version label attached to that string should not be relied on. The CVSS v4.0 assessment scores the issue separately at 8.6 (HIGH) with an exploit maturity of Proof-of-Concept, and the CVSS v2.0 score is 9.0 with complete impact across all three categories.
If the reported scope change and public exploit hold up, a single authenticated low-privilege session against an internet-reachable NAS could lead to full device compromise and impact beyond the vulnerable component itself.
There is no CISA KEV entry supplied for this CVE, so active in-the-wild exploitation is not confirmed by KEV at this time.
What's Vulnerable
- D-Link DNS-340L: versions up to and including 20260717
- D-Link DNS-345: versions up to and including 20260717
Affected CPEs: cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:* and cpe:2.3:h:d-link:dns-345:*:*:*:*:*:*:*:*.
Patch Status
The supplied source material does not include a patch, fixed version, vendor advisory, or required remediation action for CVE-2026-82692. The only vendor reference provided is D-Link's main website. Defenders should treat these devices as unpatched pending vendor guidance and restrict network exposure of the management interface accordingly.
Sources
- NVD, CVE-2026-82692 record (source:
[email protected]) - VulDB, CVE entry: https://vuldb.com/cve/CVE-2026-82692
- VulDB, Vulnerability 397180: https://vuldb.com/vuln/397180
- VulDB, CTI details: https://vuldb.com/vuln/397180/cti
- VulDB, Submission 894211: https://vuldb.com/submit/894211
- Researcher writeup (GitHub): https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-006-vulndb.md
- D-Link: https://www.dlink.com/