A publicly disclosed OS command injection flaw in the D-Link DNS-320 ShareCenter's file sharing CGI lets remote attackers who already hold privileged access to the device execute arbitrary commands, rated CVSS 9.1 (Critical).
What Is It
CVE-2026-85224 is an OS command injection vulnerability (CWE-77, CWE-78) in D-Link DNS-320 ShareCenter version 2.06B01. The flaw sits in an unknown part of the file /cgi/file_sharing.cgi, belonging to the File Sharing component. Manipulation of the fileurl argument leads to OS command injection. The attack can be launched remotely.
NVD assigns a CVSS 3.1 base score of 9.1 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low complexity, high privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. The CVSS 4.0 secondary score from the CNA is 8.5 (HIGH) and flags exploit maturity as PROOF_OF_CONCEPT. The PR:H requirement in the NVD vector is the main constraint on exploitation: an attacker needs privileged access to the device before reaching the injection point.
Why It Matters
The exploit has been publicly disclosed and may be utilized. Public availability of exploit code plus a network-reachable NAS appliance is a well-understood combination: command injection on a storage device yields code execution in the context of the web service, and the CVSS changed-scope rating indicates impact can extend beyond the vulnerable component itself. The privilege prerequisite narrows the realistic attacker to someone who has already obtained device credentials, through default or reused passwords, a prior compromise, or an insider, rather than an unauthenticated internet scanner.
This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog in the supplied data, so there is no confirmation of active in-the-wild exploitation at this time; only a proof-of-concept.
What's Vulnerable
- Vendor: D-Link
- Product: DNS-320 ShareCenter (hardware)
- Version: 2.06B01 (affected)
- Component: File Sharing,
/cgi/file_sharing.cgi - Parameter:
fileurl
Patch Status
The supplied source material contains no vendor advisory, patch, fixed version, or remediation guidance. The NVD record was published 2026-09-03 with a vulnerability status of "Received," meaning it has not yet completed NVD analysis. The DNS-320 ShareCenter is a legacy consumer NAS line; consult D-Link directly for support and firmware status. Until vendor guidance exists, restricting network exposure of the device's web interface is the only mitigation supportable from this data.
Sources
- NVD, CVE-2026-85224: https://nvd.nist.gov/vuln/detail/CVE-2026-85224
- VulDB, CVE-2026-85224: https://vuldb.com/cve/CVE-2026-85224
- VulDB, Entry 398423: https://vuldb.com/vuln/398423
- VulDB, Threat Intelligence: https://vuldb.com/vuln/398423/cti
- VulDB, Submission 894215: https://vuldb.com/submit/894215
- Researcher writeup (dxz0069): https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/DLINK-CMD-010-vulndb.md
- D-Link: https://www.dlink.com/