D-Link won’t fix critical flaw affecting 60,000 older NAS devices
ID: 80661c3f-2fc1-539b-96d3-d3f9d50f344d
STIX ID: report--80661c3f-2fc1-539b-96d3-d3f9d50f344d
Feed Name: Bleeping Computer
Threat Score
A critical command-injection vulnerability (CVE-2024-10914, CVSS 9.2) affecting multiple end-of-life D-Link NAS models allows unauthenticated remote command execution via the cgi_user_add 'name' parameter; a public exploit and FOFA scans show tens of thousands of exposed devices, and D-Link will not issue a fix, recommending device retirement or isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
