CRITICALVulnerability
CVE-2026-82691
A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Properties
- severity
- CRITICAL
- score
- 9.1
- epss_score
- 0.02108
- cve_id
- CVE-2026-82691
- vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- published_at
- 2026-08-31T12:17:58.163
- last_modified
- 2026-09-02T14:17:15.257
- epss_percentile
- 0.80565
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
DESCRIBED_BY (1)
→[Source]NVD
HAS_WEAKNESS (2)
→[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
→[Weakness]Improper Neutralization of Special Elements used in a Command ('Command Injection')
Explore deeper with Ninja Signal's threat intelligence graph