D-Link DNS-320L/327L/340L/345 CGI OS Command Injection (usb_device.cgi)
First seen Sep 2, 2026 · Updated Sep 2, 2026 · CVSS 9.1
A critical OS command injection vulnerability affects multiple D-Link NAS devices (DNS-320L, DNS-327L, DNS-340L, DNS-345) through the usb_device.cgi CGI handler. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands via the f_ups_ip parameter, and a public exploit is already available, making immediate exploitation highly likely.
Technical Analysis
The vulnerability resides in the CGI Handler component of D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 NAS devices (firmware up to 20260717), specifically in the /cgi-bin/usb_device.cgi endpoint. Insufficient input sanitization of the f_ups_ip parameter (intended for UPS device IP configuration) allows an attacker to inject and execute arbitrary OS commands with the privileges of the CGI process, typically root on embedded Linux firmware. The attack can be performed remotely without documented authentication requirements, and public exploit code exists, significantly lowering the barrier for mass exploitation and botnet recruitment (e.g., Mirai-style campaigns). Organizations using these NAS devices to host RAG document stores, vector databases, or as backend storage for AI agent pipelines could suffer data exfiltration, model/data poisoning, or full device takeover, indirectly compromising agent workflows relying on that storage.
Affected Systems
D-Link DNS-320L, DNS-327L, DNS-340L, and DNS-345 NAS devices running firmware versions up to and including build 20260717; specifically the /cgi-bin/usb_device.cgi CGI Handler component.
Indicators of Compromise
- File path: /cgi-bin/usb_device.cgi
- Vulnerable parameter: f_ups_ip
- No specific hashes, IPs, or domains disclosed in source data
Remediation Steps
- 1
Apply vendor patch
Check D-Link's security advisory page for a firmware update addressing CVE-2026-82691 and apply immediately once available.
- 2
Isolate affected devices
Remove DNS-320L/327L/340L/345 devices from direct internet exposure; place them behind a firewall or VPN and restrict CGI access to trusted management networks only.
- 3
Disable unused CGI functionality
If UPS integration via usb_device.cgi is not in use, disable the service or block access to the endpoint at the network layer.
- 4
Monitor for exploitation
Review device logs and network traffic for anomalous requests to usb_device.cgi containing shell metacharacters or unexpected command sequences in f_ups_ip.
- 5
Plan device replacement
Given these are end-of-life D-Link models, evaluate migration to actively supported NAS hardware with a stronger security update cadence.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.