CVE-2024-3273
KEV PoC largeCommand Injection in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L NAS Devices
CISA: D-Link Multiple NAS Devices Command Injection Vulnerability
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L network-attached storage devices contain a command injection flaw (CWE-77) in which attacker-controlled input is passed to an underlying system shell. The flaw can be triggered remotely, and when chained with the related CVE-2024-3272 it allows an unauthenticated attacker to execute arbitrary commands on the device without credentials. Successful exploitation gives an attacker full control over the affected NAS, providing a foothold for data theft, malware deployment, or further network compromise. Users of these legacy D-Link NAS models are affected; all hardware revisions of these products have reached end-of-life or end-of-service, so no routine security updates are being delivered through the normal lifecycle. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, indicating exploitation in the wild, with a very high EPSS probability of near-term exploitation.
What to do: Because these devices are EOL/EOS, retire and replace them per D-Link's lifecycle guidance rather than waiting for a patch; check vendor channels for any interim firmware releases. As an interim mitigation, disconnect these NAS devices from direct internet access or restrict access via firewall rules, and review device/web server logs for suspicious requests indicating command injection attempts.
| D-Link DNS-320L NAS | all hardware revisions (product is EOL/EOS; no specific version range given) |
| D-Link DNS-325 NAS | all hardware revisions (product is EOL/EOS; no specific version range given) |
| D-Link DNS-327L NAS | all hardware revisions (product is EOL/EOS; no specific version range given) |
| D-Link DNS-340L NAS | all hardware revisions (product is EOL/EOS; no specific version range given) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
- Affected
- D-Link Multiple NAS Devices
- Required action
- This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- dlink
- Products
- dns-320l firmware, dns-120 firmware, dnr-202l firmware, dns-315l firmware, dns-320 firmware, dns-320lw firmware, dns-321 firmware, dnr-322l firmware, dns-323 firmware, dns-325 firmware, dns-326 firmware, dns-327l firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H