logo

Critical RCE bug in 92,000 D-Link NAS devices now exploited in attacks

ID: 2678f529-20fd-5996-a873-8d2703c61744

STIX ID: report--2678f529-20fd-5996-a873-8d2703c61744

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Attackers are actively exploiting CVE-2024-3273 — a hardcoded account ('messagebus' with empty password) combined with a command-injection 'system' parameter — in end-of-life D-Link NAS devices to deploy a Mirai botnet variant; over 92,000 exposed devices are unpatched, exploitation was observed in the wild by GreyNoise and ShadowServer, and D-Link has issued an advisory urging owners to retire or replace affected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.