The login_mgr.cgi script in D-Link DNS-320 is vulnerable to remote code execution.
Source: NVD ↗ · CISA KEV Catalog ↗