SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  D-Link DNS-340L DNS-345 Command Injection 3

Category: IoT-ATTACKS      

OS command injection vulnerability in the Virtual Volume Handler component of D-Link DNS-340L and DNS-345 devices. The vulnerability exists in /cgi-bin/virtual_vol.cgi where the arguments f_sharename, f_target, and f_name are not properly sanitized, allowing arbitrary OS command execution.


Relevant Information