Skip to main content

Description

A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Affected by this vulnerability is the function cgi_tm_set_share of the file /cgi-bin/time_machine.cgi. The manipulation of the argument Name results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

Severity

CVSS 4.0 · CNA5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS 3.1 · CNA6.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS 3.0 · CNA6.3 MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
CVSS 2.0 · CNA6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
SSVC · CISA-ADP
Exploitationpoc
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
D-LinkDNS-120
20260205
D-LinkDNR-202L
20260205
D-LinkDNS-315L
20260205
D-LinkDNS-320
20260205
D-LinkDNS-320L
20260205
D-LinkDNS-320LW
20260205
D-LinkDNS-321
20260205
D-LinkDNR-322L
20260205
D-LinkDNS-323
20260205
D-LinkDNS-325
20260205
D-LinkDNS-326
20260205
D-LinkDNS-327L
20260205
D-LinkDNR-326
20260205
D-LinkDNS-340L
20260205
D-LinkDNS-343
20260205
D-LinkDNS-345
20260205
D-LinkDNS-726-4
20260205
D-LinkDNS-1100-4
20260205
D-LinkDNS-1200-05
20260205
D-LinkDNS-1550-04
20260205

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.