D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions by passing the cgi_set_wto command in the cmd parameter, and setting the spawned session's cookie to username=admin.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dnr 326
HWDlinkall versionsDlink Dns 320b
HWDlinkall versionsDlink Dns 320l
HWDlinkall versionsDlink Dns 322l
HWDlinkall versionsDlink Dns 325
HWDlinkall versionsDlink Dns 327l
HWDlinkall versionsDlink Dns 345
HWDlinkall versionsD Link Dnr 326 Firmware
OSD-Link≤ 1.40b03D Link Dns 320b Firmware
OSD-Link≤ 1.02b01D Link Dns 320l Firmware
OSD-Link≤ 1.03b04D Link Dns 322l Firmware
OSD-Link≤ 2.00b07D Link Dns 325 Firmware
OSD-Link≤ 1.05b03D Link Dns 327l Firmware
OSD-Link≤ 1.02D Link Dns 345 Firmware
OSD-Link≤ 1.03b06
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References
Related vulnerabilities
CVE-2024-3272CRITICAL9.8⚠ KEVPL ✓same product
D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)
CVE-2024-10915CRITICAL9.2PL ✓same product
Command injection w D-Link DNS-320/325/340L przez parametr group
CVE-2024-10914CRITICAL9.2PL ✓same product
Command injection w D-Link DNS-320/325/340L — zdalne wykonanie poleceń OS
CVE-2014-7858CRITICAL9.8PL ✓same product
Pominięcie uwierzytelnienia w D-Link DNR-326 poprzez parametr cookie
CVE-2014-7859CRITICAL9.8PL ✓same product
Stack-based buffer overflow w login_mgr.cgi urządzeń D-Link — RCE