CVE-2026-8273: D-Link DNS-320 system_mgr.cgi cgi_merge_user os command injection
A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_control/cgi_merge_user of the file /cgi-bin/system_mgr.cgi. This manipulation causes os command injection. It is possible to initiate the attack remotely.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8273?
CVE-2026-8273 has been classified with a medium severity due to the potential for os command injection.
How do I fix CVE-2026-8273?
To mitigate CVE-2026-8273, update the D-Link DNS-320 to the latest firmware version that addresses this vulnerability.
What impacts does CVE-2026-8273 pose to D-Link DNS-320 users?
CVE-2026-8273 poses a risk of unauthorized command execution, which could compromise the integrity and security of the device.
Which versions of D-Link DNS-320 are affected by CVE-2026-8273?
CVE-2026-8273 affects the D-Link DNS-320 version 2.06B01.
Is there a workaround for CVE-2026-8273?
Currently, the best approach to secure against CVE-2026-8273 is to apply the necessary firmware update as there are no specific workarounds.