CyberRota Analysis
AI-GeneratedD-Link DNS-327L and DNS-340L devices are vulnerable to remote command injection via the /cgi-bin/ve_mgr.cgi file due to improper handling of the f_dev argument. This critical flaw, with a CVSS score of 9.1, allows attackers to execute arbitrary OS commands, potentially compromising the device and the network it resides on. Organizations using these devices should prioritize immediate patching or mitigation to prevent exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_dev causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.