GHSA-97fr-949f-2h6jMediumCVSS 7.3
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exploit is publicly available and might be used.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-16329
- https://ucn9h68n9289.feishu.cn/docx/MBHDdPBz4oUXa9xCdujchmPZneg?from=from_copylink
- https://vuldb.com/cve/CVE-2026-16329
- https://vuldb.com/submit/858462
- https://vuldb.com/vuln/380694
- https://vuldb.com/vuln/380694/cti
- https://www.dlink.com
- https://github.com/advisories/GHSA-97fr-949f-2h6j