92K D-Link NAS Devices Open to Critical Command-Injection Bug
ID: c2f6c256-ee2f-59f1-80cf-510c4309debf
STIX ID: report--c2f6c256-ee2f-59f1-80cf-510c4309debf
Feed Name: Dark Reading
Date Published: 2024-04-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
A critical vulnerability (CVE-2024-3273) in several end-of-life D-Link NAS models (including DNS-340L, DNS-320L, DNS-327L, DNS-325) allows attackers to bypass authentication via a backdoor account (user=messagebus with empty password) and achieve remote command execution by injecting a base64-encoded payload into the nas_sharing.cgi "system" parameter. The flaw and a public exploit were published by researcher "netsecfish," Shadowserver reported active scans/exploitation, and D-Link — citing EOL status — will not patch the devices, advising immediate retirement of affected hardware (over ~92,000 devices online).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
