CVE-2024-8127
published 2024-08-24CVE-2024-8127: A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325…
PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.73%
93.2th percentile
A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability affects the function cgi_unzip of the file /cgi-bin/webfile_mgr.cgi of the component HTTP POST Request Handler. The manipulation of the argument path leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dnr-202l | — | — |
| d-link | dnr-322l | — | — |
| d-link | dnr-326 | — | — |
| d-link | dns-1100-4 | — | — |
| d-link | dns-120 | — | — |
| d-link | dns-1200-05 | — | — |
| d-link | dns-1550-04 | — | — |
| d-link | dns-315l | — | — |
| d-link | dns-320 | — | — |
| d-link | dns-320l | — | — |
| d-link | dns-320lw | — | — |
| d-link | dns-321 | — | — |
| d-link | dns-323 | — | — |
| d-link | dns-325 | — | — |
| d-link | dns-326 | — | — |
| d-link | dns-327l | — | — |
| d-link | dns-340l | — | — |
| d-link | dns-343 | — | — |
| d-link | dns-345 | — | — |
| d-link | dns-726-4 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
path/cgi-bin/webfile_mgr.cgi
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:24; content:"/cgi-bin/webfile_mgr.cgi"; fast_pattern; http.request_body; content:"path|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:cve,2024-8127; reference:cve,2024-8128; classtype:attempted-admin; sid:2065117; rev:1;)
bytes
path|3d| in HTTP POST body followed by shell metacharacters: |3b| (;), |0a| (\n), |60| (`), |7c| (|), |24| ($) — URL-encoded or literal
- →Target HTTP POST requests to the exact URI /cgi-bin/webfile_mgr.cgi (URI length is exactly 24 bytes); inspect the request body for the 'path=' parameter containing shell metacharacters (semicolon, newline, backtick, pipe, dollar sign) either literal or URL-encoded.
- →The vulnerability is in the function cgi_unzip of /cgi-bin/webfile_mgr.cgi; the 'path' argument is the injection point via HTTP POST — monitor for OS command separators injected into this parameter. ↗
- →The attack is remotely exploitable over plaintext HTTP (tls_state: plaintext); deploy the Snort/Suricata rule at the network perimeter and internally (sid:2065117).
- →The exploit has been publicly disclosed; treat any POST to /cgi-bin/webfile_mgr.cgi with shell metacharacters in the path parameter as a high-confidence exploitation attempt (MITRE T1190 – Exploit Public-Facing Application). ↗
- ·Affected devices (D-Link DNS/DNR series up to firmware 20240814) are end-of-life with no patch available; the vendor confirmed no fix will be issued. ↗
- ·The Snort/Suricata rule (sid:2065117) also covers CVE-2024-8128 simultaneously; detections triggered by this rule should be investigated for both CVEs.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)
suricata·2025-10-09·CVSS 5.3
CVE-2024-8127 [MEDIUM] ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)
ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:24; content:"/cgi-bin/webfile_mgr.cgi"; fast_pattern; http.request_body; content:"path|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:cve,2024-8127; reference:cve,2024-8128; classtype:attempted-admin; sid:2065117; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_09, cve CVE_2024_8127_CVE_2024_8128, deploym
No public exploits indexed.
No writeups or analysis indexed.
2024-08-24
Published