Vulnerability Intelligence Report
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
CVE-2024-3273
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
7.3
HIGH
Exploitability:3.9
Impact Score:3.4
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-77 ↗CWE-77 Command Injection
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| D-Link | DNS-320L | 20240403 (affected) |
| D-Link | DNS-325 | 20240403 (affected) |
| D-Link | DNS-327L | 20240403 (affected) |
| D-Link | DNS-340L | 20240403 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.997%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulDB · Researcher · Switzerland |
| Reserved | 2024-04-03T18:21:32 |
| Published | 2024-04-04T01:00:06 |
| Last Updated | 2025-10-21T23:05:22 |
Community Chatter & Buzz