9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Affected (23)
Products: Dlink: Dns 320l Firmware, Dns 120 Firmware, Dnr 202l Firmware, Dns 315l Firmware, Dns 320 Firmware, Dns 320lw Firmware, Dns 321 Firmware, Dnr 322l Firmware, Dns 323 Firmware, Dns 325 Firmware, Dns 326 Firmware, Dns 327l Firmware, Dnr 326 Firmware, Dns 340l Firmware, Dns 343 Firmware, Dns 345 Firmware, Dns 726 4 Firmware, Dns 1100 4 Firmware, Dns 1200 05 Firmware, Dns 1550 04 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.01.0702.2013 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 320l | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 120 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dnr 202l | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 315l | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 320 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 320lw | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 321 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dnr 322l | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 323 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.01 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 325 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 326 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.00.0409.2013 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 327l | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dnr 326 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.08 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 340l | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 343 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 345 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 726 4 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 1100 4 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 1200 05 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Dlink Dns 1550 04 | All versions |
References (12)
Source: cna@vuldb.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions RequiredVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party Advisory
Timeline
No history available yet.