D-Link DNS NAS Devices Command Injection - Vulnerability

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 1, 2025
Last Seen
December 1, 2025

D-Link DNS NAS Devices Command Injection is a remote code execution vulnerability affecting D-Link NAS devices in the DNS family.

Overview

D-Link DNS NAS Devices Command Injection is a remote code execution vulnerability affecting D-Link NAS devices in the DNS family. It allows attackers to run arbitrary commands on the device, potentially compromising the NAS and any connected networks. The flaw highlights the risk of internet-facing or poorly secured NAS appliances in both home and small business environments and underscores the need for prompt patching and access controls.

Related Threat Clusters

  • Cyber Threats: Oracle RCE and Ransomware Attacks Identified

    Recent cybersecurity reports detail multiple threats, including Oracle Concurrent Processing Remote Code Execution and various Clop ransomware variants. Affected systems include those protected by Check Point IPS and…

    2 articles · Updated December 1, 2025

Recent Intelligence Reports

  • 1st December — Research.Checkpoint · December 1, 2025

CVSS v3.1 Breakdown