logo

Critical D-Link NAS vulnerability under active exploitation

ID: a73f9bae-6df4-5cc4-8c73-cb4958777488

STIX ID: report--a73f9bae-6df4-5cc4-8c73-cb4958777488

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2024-10-17

Date Updated: 2026-07-17

...
...

**Executive Summary:** Cyble observed active exploitation of two vulnerabilities in D-Link NAS devices (CVE-2024-3272: hard-coded credentials; CVE-2024-3273: command injection) with public exploit disclosure and forum-sharing; the CGSI network detected exploitation attempts since April 9 and identified many internet-exposed devices (~94,446) and multiple IP IOCs attributed to attackers predominantly originating from China.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.