CVE-2026-85223 | D-Link DNS-340L 1.01B04 CGI /cgi-bin/dropbox.cgi callback_url/sync_interval os command injection

SecurityVulns

A vulnerability identified as very critical has been detected in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection.

This vulnerability is identified as CVE-2026-85223. The attack can be initiated remotely. Additionally, an exploit exists.VulDB Recent EntriesRead More