CyberRota Analysis
AI-GeneratedD-Link DNS-340L and DNS-345 devices are vulnerable to remote OS command injection through the manipulation of specific arguments in the /cgi-bin/iscsi_mgr.cgi file. This critical vulnerability, with a CVSS score of 9.9, allows attackers to execute arbitrary commands on the affected systems, potentially compromising their integrity and confidentiality. Organizations using these devices should prioritize immediate remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.