CVE-2024-3272
published 2024-04-04CVE-2024-3272: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to…
PriorityP193critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-05-02
Exploited in the wild
EPSS
98.04%
99.9th percentile
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dns-320l | — | — |
| d-link | dns-325 | — | — |
| d-link | dns-327l | — | — |
| d-link | dns-340l | — | — |
| dlink | dns-320l_firmware | — | — |
| dlink | dns-320l_firmware | — | — |
| dlink | dns-320l_firmware | — | — |
| dlink | dns-325_firmware | — | — |
| dlink | dns-327l_firmware | — | — |
| dlink | dns-327l_firmware | — | — |
| dlink | dns-340l_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
regex: uid=([0-9(a-z)]+) gid=([0-9(a-z)]+)
- →Detect exploitation attempts by monitoring HTTP GET requests to /cgi-bin/nas_sharing.cgi with the parameter user=messagebus and an empty passwd= field. ↗
- →The base64 value 'aWQ=' in the system= parameter decodes to 'id', indicating the attacker is probing for command execution via the system parameter. Alert on base64-encoded OS commands in this field. ↗
- →Successful exploitation responses will contain 'uid=' and 'gid=' strings in the HTTP response body, indicating OS command output was returned. ↗
- →Use FOFA query app="D_Link-DNS-ShareCenter" to identify exposed D-Link NAS devices on the internet for asset inventory and attack surface reduction. ↗
- →CVE-2024-3272 is chained with CVE-2024-3273 (command injection) to achieve unauthenticated RCE. Detection rules should look for both vulnerabilities being exploited in sequence against the same source IP. ↗
- →Exploitation of CVE-2024-3273 requires valid user= and passwd= parameters; CVE-2024-3272 supplies these by using 'messagebus' as the username with an empty password. ↗
- ·The 'messagebus' username is a standard Linux system user with no password, not a traditional backdoor account. The vulnerability is that the application accepts this system user for authentication without validating whether the account should be permitted to log in. ↗
- ·All affected D-Link models (DNS-320L, DNS-325, DNS-327L, DNS-340L) are end-of-life and will receive no patches. Detection and blocking are the only mitigations available. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qr33-7mgh-rqvr: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-3
ghsa_unreviewed·2024-04-04
CVE-2024-3272 [CRITICAL] CWE-798 GHSA-qr33-7mgh-rqvr: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-3
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
VulnCheck
D-Link Multiple NAS Devices Command Injection Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-3273 [CRITICAL] CWE-77 D-Link Multiple NAS Devices Command Injection Vulnerability
D-Link Multiple NAS Devices Command Injection Vulnerability
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.
Affected: D-Link Multiple NAS Devices
Required Action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Exploitation References: https://infosec.exchange/@greynoise/112236315274772968; https://www.greynoise.io/blog/cve-2024-3273-d-link-nas-rce-exploited-in-the-wild; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-04-09&host_type=src&vulnerability=cve-
VulnCheck
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-3272 [CRITICAL] CWE-798 D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.
Affected: D-Link Multiple NAS Devices
Required Action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.fortiguard.com/outbreak-alert/d-link-multiple-devices-attack; https://blog.checkpoint.com/research/may-2024s-most-wanted-malware-pho
CISA
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
cisa·2024-04-11·CVSS 9.8
CVE-2024-3272 [CRITICAL] CWE-798 D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
Vulnerability: D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability
Affected: D-Link Multiple NAS Devices
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.
Required Action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Notes: https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383; https://nvd.nist.gov/vuln/detail/CVE-2024-3272
Remediation Due Date: 2024-05-02
CISA
D-Link Multiple NAS Devices Command Injection Vulnerability
cisa·2024-04-11·CVSS 9.8
CVE-2024-3273 [CRITICAL] CWE-77 D-Link Multiple NAS Devices Command Injection Vulnerability
Vulnerability: D-Link Multiple NAS Devices Command Injection Vulnerability
Affected: D-Link Multiple NAS Devices
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.
Required Action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Notes: https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383; https://nvd.nist.gov/vuln/detail/CVE-2024-3273
Remediation Due Date: 2024-05-02
No detection rules found.
Nuclei
D-Link Network Attached Storage - Backdoor Account
nuclei·CVSS 9.8
CVE-2024-3272 [CRITICAL] D-Link Network Attached Storage - Backdoor Account
D-Link Network Attached Storage - Backdoor Account
A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials.
Template:
id: CVE-2024-3272
info:
name: D-Link Network Attached Storage - Backdoor Account
author: ritikchaddha
severity: critical
description: |
A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP G
arXiv
TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
arxiv_fulltext·2025-01-28
TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
TORchlight: Shedding Light on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Yumingzhi Pan^ , Zhen Ling^ Corresponding author: Prof. Zhen Ling of Southeast University, China., Yue Zhang^ , Hongze Wang^ , Guangchi Liu^ , Junzhou Luo^ , Xinwen Fu^
^ Southeast University, Email: \pymz, zhenling, wanghongze, gc-liu, jluo\@seu.edu.cn
^ Drexel University, Email: [email protected]
^ University of Massachusetts Lowell, Email: [email protected]
## Abstract
The rapidly expanding Internet of Things (IoT) landscape is shifting toward cloudless architectures, removing reliance on centralized cloud services but exposing devices directly to the internet and increasing their vulnerability to cyberattacks. Our research revealed an unexpected pattern of substantial Tor net
Checkpoint
15th April – Threat Intelligence Report
blogs_checkpoint·2024-04-15
CVE-2024-29990 15th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th April, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Japanese optics giant Hoya Corporation has been a victim of a ransomware attack that impacted its major IT infrastructure and various business divisions. Hunters International ransomware gang claimed responsibility for the attack and demanded a ransom of $10M for alleged 1.7M stolen files.
Check Point Harmony Endpoint and Th
Greynoiseio
CVE-2024-3273: D-Link NAS RCE Exploited in the Wild
blogs_greynoiseio·CVSS 9.8
[CRITICAL] CVE-2024-3273: D-Link NAS RCE Exploited in the Wild
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
https://github.com/netsecfish/dlinkhttps://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383https://vuldb.com/?ctiid.259283https://vuldb.com/?id.259283https://github.com/netsecfish/dlinkhttps://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383https://vuldb.com/?ctiid.259283https://vuldb.com/?id.259283https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-3272
2024-04-04
Published
2024-04-11
Added to CISA KEV
Exploited in the wild