Critical Flaws Leave 92,000 D-Link NAS Devices Vulnerable to Malware Attacks
ID: b5415740-d1d4-58dc-920e-559080b3e685
STIX ID: report--b5415740-d1d4-58dc-920e-559080b3e685
Feed Name: The Hacker News
Active exploitation has been reported for two D-Link NAS vulnerabilities (CVE-2024-3272, CVSS 9.8; CVE-2024-3273, CVSS 7.3) affecting legacy EoL models (DNS-320L, DNS-325, DNS-327L, DNS-340L); the flaws (hard-coded credentials and command injection in nas_sharing.cgi) permit arbitrary command execution. Observers including GreyNoise report attempts to weaponize these bugs to deliver Mirai botnet malware, and Shadowserver recommends taking affected devices offline or firewalling remote access because D-Link will not provide patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
