SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82690

CRITICAL · CVSS 9.1 EPSS 2.11% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

D-Link DNS-327L and DNS-340L devices are vulnerable to remote command injection via the /cgi-bin/ve_mgr.cgi file due to improper handling of the f_dev argument. This critical flaw, with a CVSS score of 9.1, allows attackers to execute arbitrary OS commands, potentially compromising the device and the network it resides on. Organizations using these devices should prioritize immediate patching or mitigation to prevent exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82690
Severity
CRITICAL
CVSS
9.1
EPSS
2.11%

Original NVD Description

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.