Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 22, 2026
D-Link DNS-320 uploadify.php unrestricted upload
CVE-2026-16329
Description
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
Affected products
1Patches
Vulnerability mechanics
References
6- ucn9h68n9289.feishu.cn/docx/MBHDdPBz4oUXa9xCdujchmPZnegmitreexploit
- vuldb.com/cve/CVE-2026-16329mitrethird-party-advisory
- vuldb.com/submit/858462mitrethird-party-advisory
- vuldb.com/vuln/380694mitrevdb-entrytechnical-description
- vuldb.com/vuln/380694/ctimitresignaturepermissions-required
- www.dlink.commitreproduct
News mentions
0No linked articles in our index yet.