A publicly disclosed OS command injection flaw in the D-Link DNS-340L network storage device allows a remote, low-privileged attacker to execute arbitrary commands through the Dropbox sync CGI handler.
What Is It
CVE-2026-85223 is an OS command injection vulnerability (CWE-77, CWE-78) in D-Link DNS-340L firmware 1.01B04. The flaw lives in unknown functionality of /cgi-bin/dropbox.cgi, part of the device's CGI Handler component. Manipulating the callback_url or sync_interval arguments results in command injection on the underlying system.
The attack is remote and requires no user interaction. Per the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H), an attacker needs only low privileges and low attack complexity. NVD's record notes the exploit has been made public and could be used.
Why It Matters
The CVSS 3.1 base score is 9.9 (CRITICAL): driven by a changed scope, meaning successful exploitation impacts resources beyond the vulnerable component itself. Confidentiality, integrity, and availability impacts are all rated HIGH. The CVSS 4.0 assessment scores it 8.6 (HIGH) with an exploit maturity of Proof-of-Concept, and likewise rates both vulnerable-system and subsequent-system impacts as HIGH across all three dimensions.
Command injection on a NAS appliance is a direct path to the data it stores. That a public proof-of-concept already exists collapses the window between disclosure and opportunistic use.
This CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog; no KEV entry was supplied, so there is no confirmed in-the-wild exploitation or federally mandated remediation deadline attached to it at this time.
What's Vulnerable
- Vendor: D-Link
- Product: DNS-340L (network attached storage)
- Affected version: 1.01B04
- Component: CGI Handler,
/cgi-bin/dropbox.cgi - Affected parameters:
callback_url,sync_interval - CPE:
cpe:2.3:h:d-link:dns-340l:*:*:*:*:*:*:*:*
Patch Status
No patch, fixed version, or vendor advisory is identified in the supplied source material, and no required remediation action is specified. The CVE was published 2026-09-03 and remains in NVD status Received, meaning it has not yet completed NVD analysis. Refer to D-Link's site for any vendor guidance.
Sources
- NVD, CVE-2026-85223: https://nvd.nist.gov/vuln/detail/CVE-2026-85223
- VulDB, CVE-2026-85223: https://vuldb.com/cve/CVE-2026-85223
- VulDB, Vulnerability 398422: https://vuldb.com/vuln/398422
- VulDB, Threat Intelligence (398422): https://vuldb.com/vuln/398422/cti
- VulDB, Submission 894213: https://vuldb.com/submit/894213
- Researcher write-up (GitHub, dxz0069): https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-008-vulndb.md
- D-Link: https://www.dlink.com/