A publicly disclosed OS command injection flaw in the Add-On Center component of D-Link DNS-340L NAS firmware 1.01B04 allows remote attackers with high privileges to execute arbitrary commands, carrying a CVSS 3.1 score of 9.1 (Critical).
What Is It
The vulnerability resides in /cgi-bin/addon_center.cgi, part of the Add-On Center component of the D-Link DNS-340L network-attached storage device. Manipulation of the f_name, f_url, f_flag, and f_login_user arguments leads to OS command injection. The flaw is classified under CWE-77 (Command Injection) and CWE-78 (OS Command Injection). The attack can be launched remotely over the network.
Why It Matters
The exploit has been disclosed to the public and may be used. CVSS 4.0 scoring from the CNA rates exploit maturity as Proof-of-Concept, meaning the CNA assessed that demonstration code or a documented exploitation method exists; not necessarily a weaponized, reliable exploit. The public researcher write-up (dxz0069, DLINK-CMD-007) is the disclosure referenced in the advisory data.
The CVSS 3.1 vector, AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, reflects a network-reachable, low-complexity attack requiring no user interaction, with a changed scope and complete compromise of confidentiality, integrity, and availability. Scope change means impact extends beyond the vulnerable component itself. The CVSS 4.0 assessment (base score 8.5, HIGH) likewise marks all subsequent-system impacts as HIGH. High privileges are required, which constrains the attacker's starting position but does not prevent full device takeover once credentials or an authenticated session are obtained.
What's Vulnerable
- Vendor: D-Link
- Product: DNS-340L
- Affected version: 1.01B04
- Component: Add-On Center (
/cgi-bin/addon_center.cgi) - CPE:
cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
No other versions or products are identified in the supplied advisory data.
Patch Status
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog (https://www.cisa.gov/known-exploited-vulnerabilities-catalog), active exploitation has not been confirmed by KEV, and no KEV-mandated remediation deadline or required action applies. The NVD record (https://nvd.nist.gov/vuln/detail/CVE-2026-85222) is in Received status as of its 2026-09-03 publication and lists no patch reference, fixed version, or vendor advisory beyond D-Link's general website. No remediation guidance is present in the supplied data.
Sources
- NVD, CVE-2026-85222: https://nvd.nist.gov/vuln/detail/CVE-2026-85222
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- VulDB, CVE-2026-85222: https://vuldb.com/cve/CVE-2026-85222
- VulDB, Vulnerability 398421: https://vuldb.com/vuln/398421
- VulDB, Threat Intelligence (398421): https://vuldb.com/vuln/398421/cti
- VulDB, Submission 894212: https://vuldb.com/submit/894212
- Researcher write-up (dxz0069, DLINK-CMD-007): https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-007-vulndb.md
- D-Link: https://www.dlink.com/