Junglewise Threat Intelligence

CVE-2024-3272: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

CVE-2024-3272 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-04-11

Technologies: D-Link DNS-327L, D-Link DNS-320L, D-Link DNS-340L. Vendors: D-Link.

Executive brief

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L NAS devices contain a hard-coded credential vulnerability in the /cgi-bin/nas_sharing.cgi component. A remote attacker can exploit this via a crafted HTTP GET request to the 'user' argument with the 'messagebus' input, leading to unauthorized command injection and remote code execution.

Affected products

  • D-Link DNS-320L up to 20240403
  • D-Link DNS-325 up to 20240403
  • D-Link DNS-327L up to 20240403
  • D-Link DNS-340L up to 20240403

Timeline

  • 2024-04-11: disclosed: Vulnerability disclosed and added to CISA KEV catalog.
  • 2024-04-11: kev added
  • 2024-04-11: exploited: Reported as exploited in the wild.

Related threats