A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared D-link dns-343 Sharecenter
Vendors & Products D-link dns-343 Sharecenter

Thu, 03 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection
First Time appeared D-link
D-link dns-320 Sharecenter
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dns-320_sharecenter:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dns-320 Sharecenter
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-09-03T21:45:08.564Z

Updated: 2026-09-04T17:47:33.993Z

Reserved: 2026-09-03T14:31:34.496Z

Link: CVE-2026-85224

cve-icon Vulnrichment

Updated: 2026-09-04T17:47:10.335Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T22:18:24.260

Modified: 2026-09-04T18:18:02.177

Link: CVE-2026-85224

cve-icon Redhat

No data.