D-Link will kritischen Fehler, der 60.000 ältere NAS-Geräte betrifft, nicht beheben

Teilen:

More than 60,000 D-Link network-attached storage devices that have reached end-of-life are vulnerable to a command injection vulnerability with a publicly available exploit.

The flaw, tracked as CVE-2024-10914, has a critical 9.2 severity score and is present in the ‘cgi_user_add’ command where the name parameter is insufficiently sanitized.

An unauthenticated attacker could exploit it to inject arbitrary shell commands by sending specially crafted HTTP GET requests to the devices.

The flaw impacts multiple models of D-Link network-attached storage (NAS) devices that are commonly used by small businesses:

  • DNS-320 Version 1.00
  • DNS-320LW Version 1.01.0914.2012
  • DNS-325 Version 1.01,  Version 1.02
  • DNS-340L Version 1.08

In a technical write-up that provides exploit details, security researcher Netsecfish says that leveraging the vulnerability requires sending “a crafted HTTP GET request to the NAS device with malicious input in the name parameter.”

curl "https://[Target-IP]/cgi-bin/account_mgr.cgi cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27" 

“This curl request constructs a URL that triggers the cgi_user_add command with a name parameter that includes an injected shell command,” the researcher explains.

In a security bulletin today, D-Link has confirmed that a fix for CVE-2024-10914 is not coming and the vendor recommends that users retire vulnerable products.

If that is not possible at the moment, users should at least isolate them from the public internet or place them under stricter access conditions.

The same researcher discovered in April this year an arbitrary command injection and hardcoded backdoor flaw, tracked as CVE-2024-3273, impacting mostly the same D-Link NAS models as the latest flaw.

Back then, FOFA internet scans returned 92,589 results.

Responding to the situation at the time, a D-Link spokesperson told BleepingComputer that the networking firm no longer makes NAS devices, and the impacted products had reached EoL and will not be receiving security updates.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:09 am, Juni 29, 2025
Wetter-Symbol 22°C
L: 20° | H: 22°
klarer Himmel
Luftfeuchtigkeit: 79 %
Druck: 1024 mb
Wind: 4 mph SSW
Windböe: 7 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 0%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 22°°C 0 mm 0% 7 mph 80 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 34°°C 1 mm 100% 6 mph 66 % 1022 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
20° | 32°°C 0.77 mm 77% 11 mph 68 % 1019 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
16° | 24°°C 1 mm 100% 12 mph 89 % 1019 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
15° | 22°°C 0 mm 0% 15 mph 81 % 1022 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
20° | 22°°C 0 mm 0% 7 mph 78 % 1025 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 21°°C 0 mm 0% 5 mph 80 % 1025 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 5 mph 80 % 1026 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 4 mph 58 % 1026 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 5 mph 43 % 1025 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 3 mph 35 % 1023 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 1 mph 34 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 6 mph 56 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,625.15
0.22%
Ethereum(ETH)
€2,083.09
0.73%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.87
2.02%
Solana(SOL)
€128.85
5.77%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.140286
1.86%
Shiba Inu(SHIB)
€0.000010
2.51%
Pepe(PEPE)
€0.000009
4.42%
Nach oben scrollen