Medium severity4.7NVD Advisory· Published May 11, 2026· Updated May 11, 2026
CVE-2026-8273
CVE-2026-8273
Description
A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/D-Link%20DNS-320%20%20system_mgraccount_mgrdsk_mgrapp_mgr%20Multiple%20CGI%20OS%20Command%20Injection.mdnvdExploitThird Party Advisory
- vuldb.com/submit/810082nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/362570nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/362570/ctinvdPermissions RequiredVDB Entry
- www.dlink.comnvdProduct
News mentions
0No linked articles in our index yet.