A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
The vulnerability affects the cgi_user_add function in the /cgi-bin/account_mgr.cgi?cmd=cgi_user_add file. By manipulating the 'group' parameter in the HTTP request, it is possible to inject operating system commands (OS command injection). The attack can be carried out remotely without authentication requirement, although it requires relatively high technical complexity on the attacker's side.
An attacker can execute arbitrary commands in the context of the NAS device's operating system, which may lead to complete takeover of the device, loss of confidentiality and integrity of stored data, and service unavailability.
Patches available from the manufacturer should be applied according to references. In case no update is available, consider isolating the device from the public network, restricting access to the management interface to trusted local networks only, and monitoring network traffic directed to the cgi-bin/account_mgr.cgi endpoint.
D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L in all firmware versions up to 20241028 inclusive
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDlink Dns 320
HWDlinkall versionsDlink Dns 320 Firmware
OSDlinkall versionsDlink Dns 320lw
HWDlinkall versionsDlink Dns 320lw Firmware
OSDlinkall versionsDlink Dns 325
HWDlinkall versionsDlink Dns 325 Firmware
OSDlinkall versionsDlink Dns 340l
HWDlinkall versionsDlink Dns 340l Firmware
OSDlinkall versions
Related vulnerabilities
D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)
Command injection w D-Link DNS-320 umożliwiający zdalny RCE
D-Link DNS-320: RCE przez command injection w login_mgr.cgi
Command injection w D-Link DNS-320/325/340L — zdalne wykonanie poleceń OS
Stack-based buffer overflow w login_mgr.cgi urządzeń D-Link — RCE