Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq96-v7ff-6hfp

Опубликовано: 04 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 9.9

Описание

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

EPSS

Процентиль: 75%
0.01626
Низкий

8.6 High

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.9
nvd
15 дней назад

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.

CVSS3: 9.9
fstec
2 месяца назад

Уязвимость сценария /cgi-bin/dropbox.cgi компонента CGI Handler микропрограммного обеспечения сетевых хранилищ D-Link DNS-340L, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 75%
0.01626
Низкий

8.6 High

CVSS4

9.9 Critical

CVSS3

Дефекты

CWE-77