S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Nov 26, 2024

CVE-2024-10915 Scanner

CVE-2024-10915 Scanner - Command Injection vulnerability in D-Link NAS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-10915
9.2
CVSScritical
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
DNS-320by D-Link
20241028
DNS-320LWby D-Link
20241028
DNS-325by D-Link
20241028
DNS-340Lby D-Link
20241028
Updated Aug 22, 2026View on NVD →
Detail

D-Link NAS products, such as DNS-320, DNS-320LW, DNS-325, and DNS-340L, are commonly used by small businesses and home users for data storage and sharing solutions. Networking professionals and IT enthusiasts choose D-Link for its reliable performance and affordability. These NAS devices provide functionalities such as centralized data management, remote access, and data backup. Users can configure different settings according to their needs, offering a versatile storage solution. The products are easy to set up and manage, making them popular for consumers looking to expand their data capacity efficiently. Despite their ease of use, vigilance is required to maintain these systems securely.

Command Injection vulnerabilities allow attackers to execute arbitrary commands on the host operating system via a vulnerable application. This specific vulnerability in D-Link NAS systems affects the 'group' parameter in the account management functionality. Attackers manipulate this parameter to insert and execute malicious OS commands. Such vulnerabilities are critical as they can provide attackers with deeper access to the system beyond the intended functionality. This type of injection is dangerous as it can allow unauthorized access to sensitive data or even complete control over the affected system if exploited. Effective security measures must be implemented to mitigate such vulnerabilities and protect against unauthorized system access.

Technical details of this vulnerability reveal that the endpoint '/cgi-bin/account_mgr.cgi' with the command 'cgi_user_add' is the point of exploitation. The vulnerability stems from inadequate input validation of the 'group' parameter in HTTP requests. Malicious users can manipulate this input to inject commands that the system then executes with potentially elevated privileges. The exploit involves appending commands in shell syntax to the 'group' parameter value. Attackers tend to use common payloads like 'id' or 'ifconfig' to confirm successful command injection. The vulnerability highlights the importance of validating and sanitizing all user inputs effectively.

Exploiting this vulnerability could have severe consequences, including unauthorized control over the NAS, data theft, or complete system manipulation. Once the attacker gains a foothold through command injection, they can perform actions like data exfiltration or deploying malware, leading to significant security breaches. They might escalate their privileges, gaining access to restricted areas of the system. This could result in loss of data integrity, confidentiality breaches, and denial of service. Ensuring these vulnerabilities are patched promptly is essential to safeguard the infrastructure against exploitation.

REFERENCES

Solution Advice
  • Regularly update the firmware of D-Link NAS devices to the latest version to mitigate discovered vulnerabilities.
  • Implement strict input validation techniques to prevent untrusted input manipulation.
  • Restrict access to critical NAS management functions to trusted users only.
  • Utilize security tools and monitoring systems to detect and alert on unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.