← Back to CVE List
Vulnerability Analysis
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

CVE-2024-3273

unsupported-when-assigned

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CISA KEV Nuclei Template
CVSS Base Score
7.3
HIGH
Exploitability:3.9
Impact Score:3.4
Temporal Score:-
EPSS:100.00%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2024-04-11
Ransomware Use
Unknown
KEV Due Date
2024-05-02
VulnCheck In-the-Wild
No
Nuclei Template
YES
EPSS Score
99.997%
EPSS Percentile
100.0th pct
GitHub Severity
HIGH
SSVC Exploitation
SSVC Automatable
Vulnerability Class

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD