ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Over 90,000 D

criticalRansomware exploited in the wildimportance 60CVE-2024-3273

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3273
Command Injection in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L NAS Devices

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L network-attached storage devices contain a command injection flaw (CWE-77) in which attacker-controlled input is passed to an underlying system shell. The flaw can be triggered remotely, and when chained with the related CVE-2024-3272 it allows an unauthenticated attacker to execute arbitrary commands on the device without credentials. Successful exploitation gives an attacker full control over the affected NAS, providing a foothold for data theft, malware deployment, or further network compromise. Users of these legacy D-Link NAS models are affected; all hardware revisions of these products have reached end-of-life or end-of-service, so no routine security updates are being delivered through the normal lifecycle. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-04-11, indicating exploitation in the wild, with a very high EPSS probability of near-term exploitation.

Do: Because these devices are EOL/EOS, retire and replace them per D-Link's lifecycle guidance rather than waiting for a patch; check vendor channels for any interim firmware releases. As an interim mitigation, disconnect these NAS devices from direct internet access or restrict access via firewall rules, and review device/web server logs for suspicious requests indicating command injection attempts.

9.8100% KEV PoC
  • D-Link DNS-320L NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • D-Link DNS-325 NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • D-Link DNS-327L NAS all hardware revisions (product is EOL/EOS; no specific version range given)
  • +1 more
largeon the order of tens of thousands of internet-exposed D-Link NAS devices (estimated, not confirmed by the supplied data)
Full article424 words · extracted from infosecurity-magazine.com · click to collapse

Network attached storage (NAS) vendor D-Link has urged users of end-of-life (EOL) products to retire and replace them, after news emerged of mass exploitation of legacy kit via a newly discovered vulnerability.

Security researcher “netsecfish” published details of the vulnerability, which affects various D-Link NAS devices, on March 26.

“The vulnerability lies within the nas_sharing.cgi uri, which is vulnerable due to two main issues: a backdoor facilitated by hardcoded credentials, and a command injection vulnerability via the system parameter,” they explained.

“This exploitation could lead to arbitrary command execution on the affected D-Link NAS devices, granting attackers potential access to sensitive information, system configuration alteration, or denial of service, by specifying a command, affecting over 92,000 devices on the internet.”

Read more on NAS threats: Deadbolt Ransomware Extorts Vendors and Customers

Now described as CVE-2024-3273, the high-severity vulnerability has been assigned a CVSS score of 7.3.

D-Link confirmed in an advisory that the following EOL models are exposed to exploitation of the vulnerability as they are no longer receiving firmware updates: DNS-340L, DNS-320L, DNS-327L and DNS-325.

“D-Link strongly recommends that this product be retired and cautions that any further use of this product may be a risk to devices connected to it. If US consumers continue to use these devices against D-Link’s recommendation, please make sure the device has the last known firmware which can be located on the Legacy Website links above,” it added.

“Please make sure you frequently update the device’s unique password to access its web-configuration, and always have Wi-Fi encryption enabled with a unique password.”

Non-profit threat research organization the ShadowServer Foundation confirmed that threat actors are now actively targeting vulnerable NAS devices.

“We have started to see scans/exploits from multiple IPs for CVE-2024-3273 (vulnerability in end-of-life D-Link Network Area Storage devices). This involves chaining of a backdoor & command injection to achieve RCE,” it said in a post on X (formerly Twitter).

“Exploit & PoC details are public. As there is no patch for this vulnerability, these devices should be taken offline/replaced or at least have their remote access firewalled.”

We have started to see scans/exploits from multiple IPs for CVE-2024-3273 (vulnerability in end of life D-Link Network Area Storage devices). This involves chaining of a backdoor & command injection to achieve RCE.

D-Link announcement: https://t.co/Z3HD9k1nQc

— Shadowserver (@Shadowserver) April 8, 2024

NAS devices are a popular target for botnet herders and ransomware actors as they are often managed by home users, which can mean they’re less well-protected than enterprise systems.

Image credit: JHVEPhoto / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/over-90000-dlink-nas-devices-attack/