D Link · Dns-345 · CVE-2026-82688
**Name of the Vulnerable Software and Affected Versions**
D-Link DNS-340L version 1.01B04
D-Link DNS-340L version 1.03B06
D-Link DNS-340L version 1.04.B02
D-Link DNS-340L version 1.05b04
D-Link DNS-345 version 1.01B04
D-Link DNS-345 version 1.03B06
D-Link DNS-345 version 1.04.B02
D-Link DNS-345 version 1.05b04
**Description**
An OS command injection flaw exists in the Virtual Volume Handler component. The issue occurs when the `/cgi-bin/virtual vol.cgi` endpoint fails to properly sanitize the `f sharename`, `f target`, and `f name` arguments, allowing a remote attacker to execute arbitrary operating system commands.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict access to the `/cgi-bin/virtual vol.cgi` endpoint to minimize the risk of exploitation.