CVE-2024-10915
PoC largeUnauthenticated OS Command Injection in D-Link DNS-320/320LW/325/340L NAS
CVE-2024-10915 is a critical operating system command injection (CWE-78) in the cgi_user_add function of the file /cgi-bin/account_mgr.cgi on D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L network-attached storage firmware. An attacker triggers it remotely by sending a request to /cgi-bin/account_mgr.cgi?cmd=cgi_user_add with manipulated content in the 'group' parameter; no authentication is required, but the attack is rated as high complexity and known to be difficult to exploit. Successful injection executes arbitrary OS commands on the NAS, with high impact on the device's confidentiality, integrity and availability (CVSS 4.0: 9.2). Any deployment running affected firmware — versions up to and including the 20241028 build — on these four legacy D-Link NAS models is exposed, with risk concentrated on devices whose web interface is reachable from the internet. A public proof of concept is available and the EPSS score of 79.4% (100th percentile) signals a high likelihood of exploitation attempts within 30 days, though the flaw is not yet in the CISA KEV catalog and no confirmed in-the-wild exploitation is documented.
What to do: Inventory for these four D-Link NAS models and compare firmware versions against the 20241028 build; install the newest firmware available from D-Link support for each model and review D-Link's security advisory, since the provided data shows all builds through 20241028 as affected and identifies no fixed release. Until a fix is confirmed, block direct internet access to the NAS web management interface (firewall rules or VPN-only access) and monitor for suspicious requests to /cgi-bin/account_mgr.cgi with a manipulated 'group' parameter. Given the public proof of concept, elevated EPSS, and the age of these devices, consider replacing units that must remain internet-facing.
| D-Link DNS-320 firmware | all versions up to and including 20241028 (no fixed build identified in available data) |
| D-Link DNS-320LW firmware | all versions up to and including 20241028 (no fixed build identified in available data) |
| D-Link DNS-325 firmware | all versions up to and including 20241028 (no fixed build identified in available data) |
| D-Link DNS-340L firmware | all versions up to and including 20241028 (no fixed build identified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
- Vendors
- dlink
- Products
- dns-320 firmware, dns-320lw firmware, dns-325 firmware, dns-340l firmware
- Weakness
- CWE-74, CWE-78, CWE-707
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X