SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-8272

The manipulation results in os command injection.

LOW 2.0EPSS 5.59%

Does this matter?

Lower severity and a low EPSS score (5.59%). Track it; it rarely justifies an emergency change on its own.

Description

A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/chown of the file /cgi-bin/webfile_mgr.cgi. The manipulation results in os command injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

CVSS 4.0
2.0 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
5.59% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-77, CWE-78
Affected
dlink/dns-320 firmware
Source
cna@vuldb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.