ZeroHour

CVE-2024-3272

KEV PoC large1

Hard-Coded Backdoor Credentials in End-of-Life D-Link NAS Devices

CISA: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

A hard-coded 'messagebus' account (CWE-798) in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on D-Link NAS devices lets a remote, unauthenticated attacker authenticate as a backdoor user by sending a crafted request with user=messagebus. Successful use of the backdoor grants full unauthorized access to the device's management/sharing interface (CVSS 9.8: network-exploitable, low complexity, no privileges or user interaction required). Affected devices are end-of-life D-Link NAS models — including DNS-320L, DNS-320, DNS-320LW, DNS-321, DNS-323, DNS-325, DNS-326, DNS-327L, DNS-340L, DNS-120, DNS-315L, DNR-202L and DNR-322L — which will never receive a fixed firmware release. The exploit is public, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, EPSS stands at 98%, and press reports indicate a botnet is actively targeting these devices. Roughly 92,000 internet-facing D-Link NAS devices are estimated to be exposed.

What to do: These products are end-of-life and will not be patched, so retire and replace them per D-Link's guidance. In the interim, remove any port-forwarding or remote-access rules that expose the NAS web interface (nas_sharing.cgi) to the internet and verify the backdoor 'messagebus' account cannot authenticate. Since active exploitation (including botnet deployment) is underway, check any previously exposed device for signs of compromise such as unknown accounts or unusual processes.

Affected
D-Link DNS-320LAll firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-320All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-320LWAll firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-321All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-323All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-325All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-326All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-327LAll firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-340LAll firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-120All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNS-315LAll firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
D-Link DNR-202LAll firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release
Estimated exposure
large~92,000+ internet-facing devices (public internet scans reported in security press) — Security news coverage of this flaw and its companion issue cites internet-wide scan results showing approximately 92,000 internet-facing D-Link NAS devices affected, with the total installed base of these EOL models likely somewhat higher…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CISA Known Exploited Vulnerability
Affected
D-Link Multiple NAS Devices
Required action
This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dns-320l firmware, dns-120 firmware, dnr-202l firmware, dns-315l firmware, dns-320 firmware, dns-320lw firmware, dns-321 firmware, dnr-322l firmware, dns-323 firmware, dns-325 firmware, dns-326 firmware, dns-327l firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news