Executive brief
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L NAS devices contain a hard-coded credential vulnerability in the /cgi-bin/nas_sharing.cgi component. A remote attacker can exploit this via a crafted HTTP GET request to the 'user' argument with the 'messagebus' input, leading to unauthorized command injection and remote code execution.
Affected products
- D-Link DNS-320L up to 20240403
- D-Link DNS-325 up to 20240403
- D-Link DNS-327L up to 20240403
- D-Link DNS-340L up to 20240403
Timeline
- 2024-04-11: disclosed: Vulnerability disclosed and added to CISA KEV catalog.
- 2024-04-11: kev added
- 2024-04-11: exploited: Reported as exploited in the wild.