EUVD Vulnerability Catalog

EUVD-2026-68485

Severity: CRITICAL Base Score: 9.4 CVSS Version: 4.0

Vulnerability Description

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such manipulation of the argument f_ups_ip leads to os command injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): Low
▪ Attack Requirements (AT): None
▪ Privileges Required (PR): High
▪ User Interaction (UI): None
▪ Vulnerability Confidentiality Impact (VC): High
▪ Vulnerability Integrity Impact (VI): High
▪ Vulnerability Availability Impact (VA): High
▪ Subsequent Confidentiality Impact (SC): High
▪ Subsequent Integrity Impact (SI): High
▪ Subsequent Availability Impact (SA): High
▪ E: P

Affected Vendors & Systems

Vendor D-Link

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

VulDB

EPSS Probability

0

Known Aliases
CVE-2026-82691
Published On

2026-08-31

Last Updated

2026-08-31