Executive brief
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L NAS devices contain a command injection vulnerability in the /cgi-bin/nas_sharing.cgi component. An attacker can exploit this via a crafted HTTP GET request using the 'system' argument to execute arbitrary commands. This vulnerability affects end-of-life products and is known to be exploited in the wild.
Affected products
- D-Link DNS-320L All versions up to 20240403; EOL
- D-Link DNS-325 All versions up to 20240403; EOL
- D-Link DNS-327L All versions up to 20240403; EOL
- D-Link DNS-340L All versions up to 20240403; EOL
Timeline
- 2024-04-03: disclosed: Vulnerability discovered/reported up to this date
- 2024-04-11: advisory: Initial publication date
- 2024-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-04-11: exploited: Reported as exploited in the wild by CISA and GreyNoise