CRITICAL

CVE-2024-3272

Dlink Dns 320l Firmware 2024-04-04 CVSS v3.1
CVSS
9.8
KEV

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Summary dbcve.org

Hard-coded credentials vulnerability in D-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L) in the nas_sharing.cgi component. The 'user' parameter accepts 'messagebus' as input which exposes hard-coded credentials, allowing remote unauthenticated attackers to gain administrative access via HTTP GET requests.

Mitigation

Devices are end-of-life and receive no patches; retire and replace affected devices with supported alternatives, or implement network isolation/restriction if continued operation is unavoidable.

Proof of Concept

Weakness (CWE)

CWE-798 Hard-coded Credentials

EPSS Score

98.04%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE