CVE-2026-85222

A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 21:17

Updated : 2026-09-04 14:17


NVD link : CVE-2026-85222

Mitre link : CVE-2026-85222

CVE.ORG link : CVE-2026-85222


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')