D-Link DNS-3xxL NAS Series Multiple OS Command Injection Vulnerabilities (CVE-2026-82689, CVE-2026-82692, and CVE-2026-85223)

Release Date: 31st August 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and members of the general public that use a D-Link DNS-320L, DNS-327L, DNS-340L, or DNS-345 network-attached storage (NAS) device. This alert is intended to be understood by both technical and general readers.

What is it?

CVE-2026-82689, CVE-2026-82692, and CVE-2026-85223 are three OS command injection vulnerabilities in the web-management CGI scripts of D-Link's DNS-3xxL ShareCenter NAS series, a mass-market consumer/small-office storage line sold through general electronics retailers worldwide. CVE-2026-82689 affects /cgi-bin/isomount_mgr.cgi (the "upIsoRootPath" parameter) on DNS-320L, DNS-327L, DNS-340L, and DNS-345; CVE-2026-82692 affects /cgi-bin/iscsi_mgr.cgi (the "alias"/"username"/"password"/"volume_location" parameters) on DNS-340L and DNS-345; and CVE-2026-85223 affects /cgi-bin/dropbox.cgi (the "callback_url"/"sync_interval" parameters) on DNS-340L specifically. All three allow a remote, low-privileged attacker to inject and execute arbitrary operating system commands.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-82689
  2. https://www.cve.org/CVERecord?id=CVE-2026-82692
  3. https://www.cve.org/CVERecord?id=CVE-2026-85223