logo

D-Link won’t fix critical flaw affecting 60,000 older NAS devices

ID: 80661c3f-2fc1-539b-96d3-d3f9d50f344d

STIX ID: report--80661c3f-2fc1-539b-96d3-d3f9d50f344d

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-11-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical command-injection vulnerability (CVE-2024-10914, CVSS 9.2) affecting multiple end-of-life D-Link NAS models allows unauthenticated remote command execution via the cgi_user_add 'name' parameter; a public exploit and FOFA scans show tens of thousands of exposed devices, and D-Link will not issue a fix, recommending device retirement or isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.