D-Link Routers Vulnerable to OS Command Injection Attacks

CVE-2024-10914

9.8CRITICAL

Key Information

Vendor
D-Link
Status
Dns-320 Firmware
Vendor
CVE Published:
6 November 2024

Badges

🔥 No. 1 Trending😄 Trended👾 Exploit Exists🔴 Public PoC📰 News Worthy

What is CVE-2024-10914?

CVE-2024-10914 is a critical vulnerability affecting several models of D-Link routers, specifically the DNS-320, DNS-320LW, DNS-325, and DNS-340L. This vulnerability resides in the function responsible for managing user accounts, which can be exploited to perform OS command injection attacks. If successfully exploited, an attacker could potentially execute arbitrary commands on the underlying operating system of the device, which could severely compromise the security and integrity of the affected network and systems.

Technical Details

The vulnerability is associated with the cgi_user_add function in the /cgi-bin/account_mgr.cgi file. The issue arises from improper handling of the 'name' parameter, which enables OS command injection. Although the complexity of executing such an attack is relatively high, the capability for remote exploitation underscores its significance. The vulnerability has been publicly disclosed, increasing the risk that it could be targeted by malicious actors.

Impact of the Vulnerability

  1. Remote Code Execution: Successful exploitation allows an attacker to execute arbitrary commands on the affected devices, potentially leading to complete system compromise.

  2. Network Security Breach: Compromised routers can be used as a foothold for further attacks within the network, jeopardizing sensitive data and other connected devices.

  3. Increased Attack Surface: Given that the vulnerability affects multiple D-Link router models, it presents a wide attack vector for adversaries, making it a critical point of concern for organizations utilizing these devices.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Hackers target critical flaw CVE-2024-10914 in EOL D-Link NAS Devices

The exploitation of the recently disclosed ‘won’t fix’ issue CVE-2024-10914 in legacy D-Link NAS devices began days after its disclosure.  

1 month ago

Unpatched Flaw in Legacy D-Link NAS Devices Exploited Days After Disclosure  

Exploitation attempts targeting CVE-2024-10914, a recently disclosed ‘won’t fix’ vulnerability affecting outdated D-Link NAS devices. 

1 month ago

Critical bug in EoL D-Link NAS devices now exploited in attacks

​Attackers now target a critical severity vulnerability with publicly available exploit code that affects multiple models of end-of-life D-Link network-attached storage (NAS) devices.

1 month ago

Refferences

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🔴

    Public PoC available

  • 🔥

    Vulnerability reached the number 1 worldwide trending spot

  • Vulnerability started trending

  • 👾

    Exploit known to exist

  • First article discovered by BleepingComputer

  • Vulnerability published

Collectors

NVD Database7 Proof of Concept(s)6 News Article(s)
.