CVE-2026-85224

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

  • Published Sep 3, 2026
  • CVSS 8.5 high
  • 3.6% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-85224 at the National Vulnerability Database