CRITICAL🇵🇱 Wersja polska

CVE-2024-10915

CVSS 9.2v4.0pub. 2024-11-06upd. 2024-11-08

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

🤖 AI Analysis
How it works

The vulnerability affects the cgi_user_add function in the /cgi-bin/account_mgr.cgi?cmd=cgi_user_add file. By manipulating the 'group' parameter in the HTTP request, it is possible to inject operating system commands (OS command injection). The attack can be carried out remotely without authentication requirement, although it requires relatively high technical complexity on the attacker's side.

Impact

An attacker can execute arbitrary commands in the context of the NAS device's operating system, which may lead to complete takeover of the device, loss of confidentiality and integrity of stored data, and service unavailability.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. In case no update is available, consider isolating the device from the public network, restricting access to the management interface to trusted local networks only, and monitoring network traffic directed to the cgi-bin/account_mgr.cgi endpoint.

Who is affected

D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L in all firmware versions up to 20241028 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Dlink Dns 320

    HW
    Dlink
    all versions
  • Dlink Dns 320 Firmware

    OS
    Dlink
    all versions
  • Dlink Dns 320lw

    HW
    Dlink
    all versions
  • Dlink Dns 320lw Firmware

    OS
    Dlink
    all versions
  • Dlink Dns 325

    HW
    Dlink
    all versions
  • Dlink Dns 325 Firmware

    OS
    Dlink
    all versions
  • Dlink Dns 340l

    HW
    Dlink
    all versions
  • Dlink Dns 340l Firmware

    OS
    Dlink
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2024-3272CRITICAL9.8⚠ KEVPL ✓same product

D-Link DNS-320L/325/327L/340L — zakodowane na stałe poświadczenia (hard-coded credentials)

CVE-2020-25506CRITICAL9.8⚠ KEVPL ✓same product

Command injection w D-Link DNS-320 umożliwiający zdalny RCE

CVE-2019-16057CRITICAL9.8⚠ KEVPL ✓same product

D-Link DNS-320: RCE przez command injection w login_mgr.cgi

CVE-2024-10914CRITICAL9.2PL ✓same product

Command injection w D-Link DNS-320/325/340L — zdalne wykonanie poleceń OS

CVE-2014-7859CRITICAL9.8PL ✓same product

Stack-based buffer overflow w login_mgr.cgi urządzeń D-Link — RCE