← back
CVE-2024-3273

D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

CVSS 7.3 HIGHEPSS 100.0%● KEVCWE-77
In short

D-Link NAS devices contain a command injection vulnerability in their web interface that allows attackers to execute arbitrary commands remotely by sending specially crafted HTTP requests. This affects unsupported models and could give attackers complete control over the device.

Technical detail

A command injection vulnerability exists in the /cgi-bin/nas_sharing.cgi endpoint where the 'system' parameter in HTTP GET requests is not properly sanitized, allowing remote code execution without authentication. The vulnerability affects D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L models up to firmware version 20240403; exploitation requires network access to the device's web interface.

Summary generated and translated by AI from the official description.
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →