S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 26, 2024

CVE-2024-3273 Scanner

CVE-2024-3273 scanner - Command Injection vulnerability in D-Link Network Attached Storage

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-3273
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
DNS-320Lby D-Link
20240403
DNS-325by D-Link
20240403
DNS-327Lby D-Link
20240403
DNS-340Lby D-Link
20240403
Updated Aug 22, 2026View on NVD →
Detail

D-Link Network Attached Storage (NAS) devices are commonly used in homes and small businesses for data storage and sharing. These devices allow multiple users to access and share files over a network. NAS devices are favored for their ease of use, cost-effectiveness, and ability to provide centralized storage. They are used by individuals for personal backups and by small organizations to store critical business data. Due to their network connectivity, they are susceptible to various cyber threats if not properly secured.

The vulnerability identified in the D-Link NAS devices allows an attacker to perform command injection via the HTTP GET request handler. By manipulating a specific argument in the request, attackers can execute arbitrary commands on the device. This issue affects unsupported versions of the product, and the vendor has confirmed that these devices should be retired and replaced. Exploiting this vulnerability can lead to unauthorized access and control over the NAS device.

The vulnerable endpoint is /cgi-bin/nas_sharing.cgi, and the issue arises from improper handling of the system argument in an HTTP GET request. Attackers can inject commands by encoding them in base64 format and appending them to the URL. The NAS device fails to properly sanitize this input, allowing remote command execution. Successful exploitation returns a response indicating authentication success and command execution results. This flaw makes the device susceptible to remote attacks, potentially compromising stored data.

Exploiting this command injection vulnerability can have severe consequences, including unauthorized access to the NAS device and its data. Attackers can execute arbitrary commands, leading to data theft, corruption, or deletion. The vulnerability can also be used to establish persistent backdoors, allowing ongoing unauthorized access. Additionally, compromised devices can be leveraged to launch further attacks on the internal network or other connected systems.

By using the S4E platform, you can ensure your digital assets are secure from such critical vulnerabilities. Our comprehensive scanning tools detect and report vulnerabilities, helping you take proactive measures to protect your data. Join S4E today to benefit from our advanced threat detection and exposure management services, keeping your systems safe from cyber threats.

References:

Solution Advice
  • Immediately retire and replace affected D-Link NAS devices, as they are end-of-life and no longer supported by the vendor.
  • Restrict network access to NAS devices to trusted users and networks only.
  • Regularly update and patch network devices to mitigate known vulnerabilities.
  • Implement robust network security measures, including firewalls and intrusion detection systems.
  • Educate users on safe network practices to prevent exploitation of vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.