CVE-2024-3272
KEV PoC large1Hard-Coded Backdoor Credentials in End-of-Life D-Link NAS Devices
CISA: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
A hard-coded 'messagebus' account (CWE-798) in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on D-Link NAS devices lets a remote, unauthenticated attacker authenticate as a backdoor user by sending a crafted request with user=messagebus. Successful use of the backdoor grants full unauthorized access to the device's management/sharing interface (CVSS 9.8: network-exploitable, low complexity, no privileges or user interaction required). Affected devices are end-of-life D-Link NAS models — including DNS-320L, DNS-320, DNS-320LW, DNS-321, DNS-323, DNS-325, DNS-326, DNS-327L, DNS-340L, DNS-120, DNS-315L, DNR-202L and DNR-322L — which will never receive a fixed firmware release. The exploit is public, the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, EPSS stands at 98%, and press reports indicate a botnet is actively targeting these devices. Roughly 92,000 internet-facing D-Link NAS devices are estimated to be exposed.
What to do: These products are end-of-life and will not be patched, so retire and replace them per D-Link's guidance. In the interim, remove any port-forwarding or remote-access rules that expose the NAS web interface (nas_sharing.cgi) to the internet and verify the backdoor 'messagebus' account cannot authenticate. Since active exploitation (including botnet deployment) is underway, check any previously exposed device for signs of compromise such as unknown accounts or unusual processes.
| D-Link DNS-320L | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-320 | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-320LW | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-321 | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-323 | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-325 | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-326 | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-327L | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-340L | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-120 | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNS-315L | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
| D-Link DNR-202L | All firmware versions up to 2024-04-03 (up to 20240403); product is end-of-life, no fixed release |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
- Affected
- D-Link Multiple NAS Devices
- Required action
- This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dns-320l firmware, dns-120 firmware, dnr-202l firmware, dns-315l firmware, dns-320 firmware, dns-320lw firmware, dns-321 firmware, dnr-322l firmware, dns-323 firmware, dns-325 firmware, dns-326 firmware, dns-327l firmware
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H