logo

92K D-Link NAS Devices Open to Critical Command-Injection Bug

ID: c2f6c256-ee2f-59f1-80cf-510c4309debf

STIX ID: report--c2f6c256-ee2f-59f1-80cf-510c4309debf

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-04-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

A critical vulnerability (CVE-2024-3273) in several end-of-life D-Link NAS models (including DNS-340L, DNS-320L, DNS-327L, DNS-325) allows attackers to bypass authentication via a backdoor account (user=messagebus with empty password) and achieve remote command execution by injecting a base64-encoded payload into the nas_sharing.cgi "system" parameter. The flaw and a public exploit were published by researcher "netsecfish," Shadowserver reported active scans/exploitation, and D-Link — citing EOL status — will not patch the devices, advising immediate retirement of affected hardware (over ~92,000 devices online).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.