ZeroHour
Security Affairspublished ()ingested @securityaffairs

Hackers target critical flaw CVE-2024-10914 in EOL D

criticalVulnerabilityimportance 60CVE-2024-10914

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-10914
OS Command Injection in D-Link DNS-320/320LW/325/340L NAS Firmware

CVE-2024-10914 is a critical OS command injection flaw (CWE-74/CWE-78/CWE-707) in the cgi_user_add function of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add on D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L network-attached storage devices. A remote, unauthenticated attacker can trigger it by manipulating the 'name' argument sent to that CGI endpoint, injecting operating system commands that the device executes. Successful exploitation yields arbitrary command execution on the NAS, giving the attacker control of the device — a profile attractive for follow-on actions such as botnet recruitment, consistent with recent IoT botnet activity. Affected devices are the DNS-320, DNS-320LW, DNS-325, and DNS-340L, which news reports describe as end-of-life D-Link NAS models, with all firmware up to 20241028 listed as vulnerable. A public proof-of-concept is available, the EPSS score is 96.2% (top percentile, indicating very high likelihood of exploitation within 30 days), and news headlines indicate hackers are actively targeting the flaw, though it is not yet in CISA KEV.

Do: Owners of DNS-320, DNS-320LW, DNS-325, and DNS-340L devices should check D-Link's support pages for updated firmware or end-of-life guidance and apply any fix the vendor publishes. Because the flaw is reachable via /cgi-bin/account_mgr.cgi?cmd=cgi_user_add, block or restrict remote (WAN) access to the device's web management interface — and consider blocking that specific endpoint — until patched; these EOL devices may never receive an update, in which case retiring or isolating them behind a restricted network is the safest option.

9.296% PoC
  • D-Link DNS-320 firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-320LW firmware up to and including 20241028 (all listed firmware)
  • D-Link DNS-325 firmware up to and including 20241028 (all listed firmware)
  • +1 more
large≈ tens of thousands of internet-exposed NAS devices (10k–100k range; exact counts unknown)
Full article340 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 14, 2024

The exploitation of the recently disclosed ‘won’t fix’ issue CVE-2024-10914 in legacy D-Link NAS devices began days after its disclosure.  

Days after D-Link announced it wouldn’t patch a critical vulnerability, tracked as CVE-2024-10914 (CVSS score of 9.8), in legacy D-Link NAS devices, that threat actors started attempting to exploit.

The vulnerability CVE-2024-10914 is a command injection issue that impacts D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028.

The flaw could allow remote OS command injection via the cgi_user_add function, according to the advisory the exploitation is complex but possible due to the public availability of an exploit.

The vulnerability resides in the account_mgr.cgi URI of certain D-Link NAS devices. The bug stems for the handling of the name parameter used within the CGI script cgi_user_add command.

“A command injection vulnerability has been identified in the account_mgr.cgi URI of certain D-Link NAS devices. Specifically, the vulnerability exists in the handling of the name parameter used within the CGI script cgi_user_add command.” reads the post published by Netsecfish. “This flaw allows an unauthenticated attacker to inject arbitrary shell commands through crafted HTTP GET requests, affecting over 61,000 devices on the Internet.”

An unauthenticated attacker could exploit the flaw to inject arbitrary shell commands through crafted HTTP GET requests.

“A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high.” reads the advisory. “The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.”

Shadowserver Foundation researchers observed CVE-2024-10914 explotation attempts starting on November 12th. The experts observed roughly 1,100 Internet-facing devices potentially vulnerable to this issue., most of them in the UK, Hungary, and France.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, D-Link NAS)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170995/iot/cve-2024-10914-d-link-nas-flaw-exploited.html