Unrated severityNVD Advisory· Published Jul 21, 2026· Updated Jul 23, 2026
D-Link DNS-320 multi_uploadify.php unrestricted upload
CVE-2026-16332
Description
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected products
1Patches
Vulnerability mechanics
References
6- ucn9h68n9289.feishu.cn/docx/EbAkdl1v8oC3Q3xAEJLcZFcZnMYmitreexploit
- vuldb.com/cve/CVE-2026-16332mitrethird-party-advisory
- vuldb.com/submit/858465mitrethird-party-advisory
- vuldb.com/vuln/380698mitrevdb-entrytechnical-description
- vuldb.com/vuln/380698/ctimitresignaturepermissions-required
- www.dlink.commitreproduct
News mentions
0No linked articles in our index yet.