CVE-2026-16331: D-Link DNS-320 save_ajax.php unrestricted upload
A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/saveajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16331?
The severity of CVE-2026-16331 is rated high with a score of 7.3.
How does CVE-2026-16331 affect D-Link DNS-320?
CVE-2026-16331 allows for unrestricted file uploads through a vulnerability in the save_ajax.php file.
What types of attacks can be carried out due to CVE-2026-16331?
Exploiting CVE-2026-16331 can enable attackers to execute remote code through malicious file uploads.
What is the risk associated with CVE-2026-16331?
CVE-2026-16331 carries a risk score of 52, indicating a significant threat to affected systems.
Are there any public disclosures related to CVE-2026-16331?
Yes, CVE-2026-16331 has been publicly disclosed, detailing its potential impacts and exploitability.