Critical RCE bug in 92,000 D-Link NAS devices now exploited in attacks
ID: 2678f529-20fd-5996-a873-8d2703c61744
STIX ID: report--2678f529-20fd-5996-a873-8d2703c61744
Feed Name: Bleeping Computer
Threat Score
Attackers are actively exploiting CVE-2024-3273 — a hardcoded account ('messagebus' with empty password) combined with a command-injection 'system' parameter — in end-of-life D-Link NAS devices to deploy a Mirai botnet variant; over 92,000 exposed devices are unpatched, exploitation was observed in the wild by GreyNoise and ShadowServer, and D-Link has issued an advisory urging owners to retire or replace affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
