logo

No Fix For Critical Vulnerability In Legacy D-Link NAS Devices

ID: 7de03daf-09cb-5bf6-a72a-de4c985b27e3

STIX ID: report--7de03daf-09cb-5bf6-a72a-de4c985b27e3

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

**CVE-2024-10914:** A critical (CVSS 9.2) unauthenticated command-injection flaw in D-Link NAS devices (account_mgr.cgi handling of the name parameter in cgi_user_add) affects several end-of-life models (DNS-320, DNS-320LW, DNS-325, DNS-340L). The vulnerability allows remote arbitrary command execution via a simple HTTP GET, a FOFA scan found ~61,000 exposed devices, and D-Link recommends retiring or isolating affected devices since no patches will be provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.