CVE-2026-16330: D-Link DNS-320 uploadify.php unrestricted upload
A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=fromcopylink causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16330?
CVE-2026-16330 has a severity rating of high, scoring 7.3 on the CVSS scale.
How do I fix CVE-2026-16330?
To fix CVE-2026-16330, update the D-Link DNS-320 firmware to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-16330?
CVE-2026-16330 is classified as a malicious file upload vulnerability.
What impact does CVE-2026-16330 have on users?
CVE-2026-16330 allows remote attackers to upload malicious files, potentially compromising the system.
Which software is affected by CVE-2026-16330?
CVE-2026-16330 affects the D-Link DNS-320 version 1.0.2.