ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Flaws Leave 92,000 D-Link NAS Devices Vulnerable to Malware Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3273
+1 in the same advisory: …3272
Command Injection in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L NAS Devices

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L network-attached storage devices contain a command injection flaw (CWE-77) in which attacker-controlled input is passed to an underlying system shell. The flaw can be triggered remotely, and when chained with the related CVE-2024-3272 it allows an unauthenticated attacker to execute arbitrary commands on the device without credentials. Successful exploitation gives an attacker full control over the affected NAS, providing a foothold for data theft, malware deployment, or further network compromise. Users of these legacy D-Link NAS models are affected; all hardware revisions of these products have reached end-of-life or end-of-service, so no routine security updates are being delivered through the normal lifecycle. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, indicating exploitation in the wild, with a very high EPSS probability of near-term exploitation.

Do: Because these devices are EOL/EOS, retire and replace them per D-Link's lifecycle guidance rather than waiting for a patch; check vendor channels for any interim firmware releases. As an interim mitigation, disconnect these NAS devices from direct internet access or restrict access via firewall rules, and review device/web server logs for suspicious requests indicating command injection attempts.

9.8100% KEV PoC
  • D-Link DNS-320L NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • D-Link DNS-325 NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • D-Link DNS-327L NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • +1 more
largeon the order of tens of thousands of internet-exposed D-Link NAS devices (estimated, not confirmed by the supplied data)
Full article392 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 09, 2024Botnet / Vulnerability

Threat actors are actively scanning and exploiting a pair of security flaws that are said to affect as many as 92,000 internet-exposed D-Link network-attached storage (NAS) devices.

Tracked as CVE-2024-3272 (CVSS score: 9.8) and CVE-2024-3273 (CVSS score: 7.3), the vulnerabilities impact legacy D-Link products that have reached end-of-life (EoL) status. D-Link, in an advisory, said it does not plan to ship a patch and instead urges customers to replace them.

"The vulnerability lies within the nas_sharing.cgi uri, which is vulnerable due to two main issues: a backdoor facilitated by hard-coded credentials, and a command injection vulnerability via the system parameter," security researcher who goes by the name netsecfish said in late March 2024.

Successful exploitation of the flaws could lead to arbitrary command execution on the affected D-Link NAS devices, granting threat actors the ability to access sensitive information, alter system configurations, or even trigger a denial-of-service (DoS) condition.

The issues affect the following models -

  • DNS-320L
  • DNS-325
  • DNS-327L, and
  • DNS-340L

Threat intelligence firm GreyNoise said it observed attackers attempting to weaponize the flaws to deliver the Mirai botnet malware, thus making it possible to remotely commandeer the D-Link devices.

In the absence of a fix, the Shadowserver Foundation is recommending that users either take these devices offline or have remote access to the appliance firewalled to mitigate potential threats.

The findings once again illustrate that Mirai botnets are continuously adapting and incorporating new vulnerabilities into their repertoire, with threat actors swiftly developing new variants that are designed to abuse these issues to breach as many devices as possible.

With network devices becoming common targets for financially motivated and nation-state-linked attackers, the development comes as Palo Alto Networks Unit 42 revealed that threat actors are increasingly switching to malware-initiated scanning attacks to flag vulnerabilities in target networks.

"Some scanning attacks originate from benign networks likely driven by malware on infected machines," the company said.

"By launching scanning attacks from compromised hosts, attackers can accomplish the following: Covering their traces, bypassing geofencing, expanding botnets, [and] leveraging the resources of these compromised devices to generate a higher volume of scanning requests compared to what they could achieve using only their own devices."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/04/critical-flaws-leave-92000-d-link-nas.html