CVE-2024-3273

Scores

EPSS

0.944high94.4%
0%20%40%60%80%100%

Percentile: 94.4%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-77

Related Vulnerabilities

Exploits

Exploit ID: CVE-2024-3273

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Vulnerable Software (20)

Type: Configuration

Vendor: dlink

Product: dnr-202l_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dnr-202l_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dnr-322l_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dnr-322l_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dnr-326_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dnr-326_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-1100-4_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-1100-4_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-1200-05_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-1200-05_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-120_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-120_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-1550-04_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-1550-04_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-315l_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-315l_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-320_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-320_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR"...

Source: nvd

Type: Configuration

Vendor: dlink

Product: dns-320l_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:dlink:dns-320l_firmware:1.01.0702.2013:*:*:*:*:*:*:*",          "vulnerable": true        },        {       ...

Source: nvd