cbcvebase.
CVE-2024-3274
published 2024-04-04

CVE-2024-3274: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic…

PriorityP351medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EXPLOIT
EPSS
33.48%
98.2th percentile
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/info.cgi of the component HTTP GET Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259285 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Affected

3 ranges
VendorProductVersion rangeFixed in
d-linkdns-320l
d-linkdns-320lw
d-linkdns-327l

Detection & IOCsextracted from sources · hover to see the quote

path/cgi-bin/info.cgi
commandGET /cgi-bin/info.cgi HTTP/1.1
otherbody contains Model=, Build=, Macaddr=
  • Send an unauthenticated HTTP GET request to /cgi-bin/info.cgi; a vulnerable device responds with HTTP 200 and a body containing the strings 'Model=', 'Build=', and 'Macaddr='.
  • FOFA fingerprint query to identify exposed D-Link ShareCenter devices: body="Text:In order to access the ShareCenter"
  • ·This vulnerability affects only end-of-life D-Link products (DNS-320L, DNS-320LW, DNS-327L up to firmware 20240403); the vendor has confirmed no patch will be issued.
  • ·The exploit requires no authentication, no user interaction, and is remotely exploitable over the network (CVSS AV:N/AC:L/PR:N/UI:N).

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.