CVE-2024-8128
published 2024-08-24CVE-2024-8128: A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L…
PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.03%
94.2th percentile
A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This issue affects the function cgi_add_zip of the file /cgi-bin/webfile_mgr.cgi of the component HTTP POST Request Handler. The manipulation of the argument path leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dnr-202l | — | — |
| d-link | dnr-322l | — | — |
| d-link | dnr-326 | — | — |
| d-link | dns-1100-4 | — | — |
| d-link | dns-120 | — | — |
| d-link | dns-1200-05 | — | — |
| d-link | dns-1550-04 | — | — |
| d-link | dns-315l | — | — |
| d-link | dns-320 | — | — |
| d-link | dns-320l | — | — |
| d-link | dns-320lw | — | — |
| d-link | dns-321 | — | — |
| d-link | dns-323 | — | — |
| d-link | dns-325 | — | — |
| d-link | dns-326 | — | — |
| d-link | dns-327l | — | — |
| d-link | dns-340l | — | — |
| d-link | dns-343 | — | — |
| d-link | dns-345 | — | — |
| d-link | dns-726-4 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort
alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:24; content:"/cgi-bin/webfile_mgr.cgi"; fast_pattern; http.request_body; content:"path|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:cve,2024-8127; reference:cve,2024-8128; classtype:attempted-admin; sid:2065117; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_09, cve CVE_2024_8127_CVE_2024_8128, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_10_09, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application; target:dest_ip;)
bytes
path=<payload containing ; | \n ` $ or URL-encoded equivalents>
- →Target HTTP POST requests to /cgi-bin/webfile_mgr.cgi with a URI length of exactly 24 bytes; the injection is carried in the `path` POST body parameter.
- →Flag POST body `path` values containing shell metacharacters or their URL-encoded equivalents: semicolon (;/%3B), newline (\n/%0A), backtick (`/%60), pipe (|/%7C), or dollar sign ($/%24) — all classic command-injection delimiters.
- →The vulnerability is in the `cgi_add_zip` function of the webfile_mgr.cgi HTTP POST Request Handler; focus analysis on that function's handling of the `path` argument.
- →Traffic is expected in plaintext (no TLS); deploy the signature at the perimeter and internally.
- →The exploit has been publicly disclosed; treat any matching traffic as high-confidence attempted admin-level exploitation (MITRE T1190 – Exploit Public-Facing Application).
- ·All affected D-Link models (DNS-120, DNR-202L, DNS-315L, DNS-320/L/LW, DNS-321, DNR-322L, DNS-323, DNS-325/326/327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05, DNS-1550-04) are end-of-life with no patch available; detection is the only mitigation short of device replacement.
- ·The Snort/Suricata rule (sid:2065117) covers both CVE-2024-8127 and CVE-2024-8128 simultaneously; a single alert may correspond to either CVE depending on which CGI function is targeted.
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)
suricata·2025-10-09·CVSS 5.3
CVE-2024-8127 [MEDIUM] ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)
ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS D-Link webfile_mgr.cgi path Parameter Command Injection Attempt (CVE-2024-8127, CVE-2024-8128)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:24; content:"/cgi-bin/webfile_mgr.cgi"; fast_pattern; http.request_body; content:"path|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:cve,2024-8127; reference:cve,2024-8128; classtype:attempted-admin; sid:2065117; rev:1; metadata:affected_product D_Link, attack_target Networking_Equipment, tls_state plaintext, created_at 2025_10_09, cve CVE_2024_8127_CVE_2024_8128, deploym
No public exploits indexed.
No writeups or analysis indexed.
2024-08-24
Published