medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-3274 Scanner

CVE-2024-3274 Scanner - Information Disclosure vulnerability in D-LINK DNS-320L, DNS-320LW, and DNS-327L

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-3274
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259285 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
DNS-320Lby D-Link
20240403
DNS-320LWby D-Link
20240403
DNS-327Lby D-Link
20240403
dns-320lby d-link
20240403
Updated Aug 22, 2026View on NVD →
Detail

The D-LINK DNS-320L, DNS-320LW, and DNS-327L are network-attached storage devices used primarily by small businesses and home networks. These devices allow for the storage and sharing of files over a network, which can be accessed remotely. They are popular for their ease of use and efficient file management capabilities. Users span from individuals for personal file storage to small offices needing a central data repository. With features enabling remote access, these devices are integral in scenarios where data needs to be shared quickly and securely across users and locations.

This information disclosure vulnerability exposes sensitive data via an HTTP GET request. Attackers can exploit this by sending crafted requests to the affected "/cgi-bin/info.cgi" endpoint, retrieving configuration details that should not be publicly accessible. Information such as device model, build version, and MAC addresses can be disclosed, posing a potential risk for further exploitation. The vulnerability arises due to inadequate access control checks or improper handling of user input.

The technical root of the vulnerability lies within the HTTP GET request handler of the device, specifically in the "/cgi-bin/info.cgi" endpoint. This endpoint, when queried, can return sensitive information which should ideally be restricted. The response includes key-value pairs that contain device configuration details, which an unauthorized user could leverage to gather intelligence. The vulnerability is straightforward and can be checked by examining the HTTP status code and response body. In typical scenarios, a status code of 200 along with specific model details indicates the presence of this issue.

If this vulnerability is exploited, malicious individuals could gather sensitive network device configuration data. This exposure could lead to unauthorized access attempts, targeted attacks on the devices, or broader network security breaches. An attacker armed with disclosed device specifications and configurations might exploit other vulnerabilities or use the data for phishing or social engineering attacks. The integrity and confidentiality of the network could be compromised, risking both data loss and privacy concerns.

REFERENCES:

Solution Advice
  • Update the firmware of the affected D-LINK devices to the latest version provided by the manufacturer to mitigate the vulnerability.
  • Implement network segmentation and limit access to the storage devices to trusted network zones.
  • Enforce strong authentication methods for accessing device management interfaces.
  • Regularly audit access logs and configure alerts for any unusual activities.
  • Consider disabling or securing the "/cgi-bin/info.cgi" endpoint if not required for functional operation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-3274 Scanner - Information Disclosure vulnerability in D-LINK DNS-320L, DNS-320LW, and DNS-327L S4E