PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
CVE

CVE-2024-10915

9.2
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
dns-320dns-320lwdns-325dns-340ldns-320_firmwaredns-320lw_firmware
Updated Sep 18, 2026View on NVD →
S4E scanner

CVE history: dns-320

Predict next CVE date with AI

Monitor this CVE on your assets

S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.

Create a free account →