Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 22, 2026
D-Link DNS-320 save_ajax.php unrestricted upload
CVE-2026-16331
Description
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected products
1Patches
Vulnerability mechanics
References
6- ucn9h68n9289.feishu.cn/docx/UZ6id3F1Joqlpxxn3NFcL8r7nHbmitreexploit
- vuldb.com/cve/CVE-2026-16331mitrethird-party-advisory
- vuldb.com/submit/858464mitrethird-party-advisory
- vuldb.com/vuln/380697mitrevdb-entrytechnical-description
- vuldb.com/vuln/380697/ctimitresignaturepermissions-required
- www.dlink.commitreproduct
News mentions
0No linked articles in our index yet.