logo

Over 92,000 exposed D-Link NAS devices have a backdoor account

ID: 71b68873-1e86-5ead-a609-eaf19b5cd53c

STIX ID: report--71b68873-1e86-5ead-a609-eaf19b5cd53c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-06

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A researcher disclosed CVE-2024-3273: a hardcoded account and a base64-encoded command injection vulnerability in /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS models, enabling remote arbitrary command execution. Netsecfish reports over 92,000 exposed devices and D-Link states the affected models are EOL with no patches, advising users to retire or replace them.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.