← All Advisories

D-Link DNS-320 ShareCenter 2.06B01 File Sharing CGI Passes the fileurl Parameter Unsanitized to the Shell, Enabling Remote Code Execution by Authenticated Admin Users

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-85224

Key Details

CVECVE-2026-85224
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-09-04
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection'))

What to Know

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-85224
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-85224