CyberRota Analysis
AI-GeneratedD-Link DNS-340L and DNS-345 devices running specific firmware versions are vulnerable to OS command injection through the manipulation of parameters in the Virtual Volume Handler component. This critical vulnerability allows remote attackers to execute arbitrary commands on the affected systems, potentially compromising their integrity and confidentiality. Organizations using these devices should prioritize immediate patching or mitigation measures to safeguard against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual Volume Handler. The manipulation of the argument f_sharename/f_target/f_name leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.