← Back to CVE List
Vulnerability Intelligence Report
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

CVE-2024-3273

unsupported-when-assigned

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
7.3
HIGH
Exploitability:3.9
Impact Score:3.4
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-77 ↗CWE-77 Command Injection

Affected Products & Versions

Vendor Product Affected Versions
D-Link DNS-320L 20240403 (affected)
D-Link DNS-325 20240403 (affected)
D-Link DNS-327L 20240403 (affected)
D-Link DNS-340L 20240403 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.997%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulDB · Researcher · Switzerland
Reserved2024-04-03T18:21:32
Published2024-04-04T01:00:06
Last Updated2025-10-21T23:05:22

LINK COPIED TO CLIPBOARD