A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. The affected element is the function cgi_check_rsync_rw of the file /cgi-bin/remote_backup.cgi. The manipulation of the argument ip results in command injection. The attack can be executed remotely. The exploit has been made public and could be used.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-21 15:16
Updated : 2026-07-21 17:07
NVD link : CVE-2026-16448
Mitre link : CVE-2026-16448
CVE.ORG link : CVE-2026-16448
JSON object : View
Products Affected
No product.
