D-Link Routers Vulnerable to OS Command Injection Attacks
CVE-2024-10914
Key Information
- Vendor
- D-Link
- Status
- Dns-320 Firmware
- Vendor
- CVE Published:
- 6 November 2024
Badges
What is CVE-2024-10914?
CVE-2024-10914 is a critical vulnerability affecting several models of D-Link routers, specifically the DNS-320, DNS-320LW, DNS-325, and DNS-340L. This vulnerability resides in the function responsible for managing user accounts, which can be exploited to perform OS command injection attacks. If successfully exploited, an attacker could potentially execute arbitrary commands on the underlying operating system of the device, which could severely compromise the security and integrity of the affected network and systems.
Technical Details
The vulnerability is associated with the cgi_user_add
function in the /cgi-bin/account_mgr.cgi
file. The issue arises from improper handling of the 'name' parameter, which enables OS command injection. Although the complexity of executing such an attack is relatively high, the capability for remote exploitation underscores its significance. The vulnerability has been publicly disclosed, increasing the risk that it could be targeted by malicious actors.
Impact of the Vulnerability
-
Remote Code Execution: Successful exploitation allows an attacker to execute arbitrary commands on the affected devices, potentially leading to complete system compromise.
-
Network Security Breach: Compromised routers can be used as a foothold for further attacks within the network, jeopardizing sensitive data and other connected devices.
-
Increased Attack Surface: Given that the vulnerability affects multiple D-Link router models, it presents a wide attack vector for adversaries, making it a critical point of concern for organizations utilizing these devices.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Hackers target critical flaw CVE-2024-10914 in EOL D-Link NAS Devices
The exploitation of the recently disclosed ‘won’t fix’ issue CVE-2024-10914 in legacy D-Link NAS devices began days after its disclosure.
1 month ago
Unpatched Flaw in Legacy D-Link NAS Devices Exploited Days After Disclosure
Exploitation attempts targeting CVE-2024-10914, a recently disclosed ‘won’t fix’ vulnerability affecting outdated D-Link NAS devices.
1 month ago
Critical bug in EoL D-Link NAS devices now exploited in attacks
Attackers now target a critical severity vulnerability with publicly available exploit code that affects multiple models of end-of-life D-Link network-attached storage (NAS) devices.
1 month ago
Refferences
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🔴
Public PoC available
- 🔥
Vulnerability reached the number 1 worldwide trending spot
Vulnerability started trending
- 👾
Exploit known to exist
First article discovered by BleepingComputer
Vulnerability published