Vulnerabilities in end-of-life D-Link devices are being exploited, CISA says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3273 +1 in the same advisory: …3272 | Command Injection in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L NAS Devices D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L network-attached storage devices contain a command injection flaw (CWE-77) in which attacker-controlled input is passed to an underlying system shell. The flaw can be triggered remotely, and when chained with the related CVE-2024-3272 it allows an unauthenticated attacker to execute arbitrary commands on the device without credentials. Successful exploitation gives an attacker full control over the affected NAS, providing a foothold for data theft, malware deployment, or further network compromise. Users of these legacy D-Link NAS models are affected; all hardware revisions of these products have reached end-of-life or end-of-service, so no routine security updates are being delivered through the normal lifecycle. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, indicating exploitation in the wild, with a very high EPSS probability of near-term exploitation. Do: Because these devices are EOL/EOS, retire and replace them per D-Link's lifecycle guidance rather than waiting for a patch; check vendor channels for any interim firmware releases. As an interim mitigation, disconnect these NAS devices from direct internet access or restrict access via firewall rules, and review device/web server logs for suspicious requests indicating command injection attempts. | 9.8 | 100% | KEV PoC |
| largeon the order of tens of thousands of internet-exposed D-Link NAS devices (estimated, not confirmed by the supplied data) |
Full article311 words · extracted from therecord.media · click to collapse
The U.S. government has confirmed reports by cybersecurity companies and researchers that some older D-Link devices are being exploited by threat actors. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-3273 and CVE-2024-3272 to its Known Exploited Vulnerabilities list on Thursday, warning federal agencies that they have until May 2 to retire or replace D-Link hardware that in some cases could be a decade old. The network-attached devices are used to store and access files remotely. Since Monday, researchers at cybersecurity organizations GreyNoise and ShadowServer have reported that the devices are being attacked widely following the release of an advisory by D-Link about the vulnerabilities on April 4. GreyNoise warned that as many as 92,000 devices may be at risk of exploitation due to the vulnerabilities. The affected models are DNS-320L, DNS-325, DNS-327L, and DNS-340L. D-Link said it was told about the vulnerabilities by a researcher on March 26 and warned customers that the devices had reached their end of life and would no longer receive device software updates and security patches. The devices are “no longer supported by D-Link” the company said, writing that they recommend they “be retired and replaced.” “Typically for these products, D-Link will be unable to resolve device or firmware issues since all development and customer support has ceased,” D-Link said. “D-Link strongly recommends that this product be retired and cautions that any further use of this product may be a risk to devices connected to it.” ShadowServer said exploits and proof of concept (POC) code is available — meaning that without a patch, the devices are vulnerable with no remedy. Bleeping Computer was first to report on the vulnerabilities. GreyNoise noted that the attack method to exploit the bugs is typically used by “botnet operators to try to execute malware for every possible CPU architecture in the expectation that at least one will work.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/dlink-devices-exploited-vulnerabilities-cisa