D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
100Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 9.2epss 97%
de la publicación al arma3 días
Publicada en NVD6 nov
1ª PoC+3d
VulnCheck+7d
probabilidad de explotación
97%top 1% de las CVE
explotación observada
síVulnCheck
29 exploit(s) público(s)
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
PoCs públicas encontradas — 29
githubgithub.com/verylazytech/CVE-2024-10914★ 48githubgithub.com/imnotcha0s/CVE-2024-10914★ 14githubgithub.com/ThemeHackers/CVE-2024-10914★ 9githubgithub.com/K3ysTr0K3R/CVE-2024-10914-EXPLOIT★ 7githubgithub.com/redspy-sec/D-Link★ 4githubgithub.com/yenyangmjaze/cve-2024-10914★ 1githubgithub.com/TH-SecForge/CVE-2024-10914★ 1githubgithub.com/Bu0uCat/D-Link-NAS-CVE-2024-10914-★ 1githubgithub.com/Egi08/CVE-2024-10914★ 0githubgithub.com/retuci0/cve-2024-10914-port★ 0githubgithub.com/jahithoque/CVE-2024-10914-Exploit★ 0githubgithub.com/dragonXZH/CVE-2024-10914★ 0githubgithub.com/Tamirido30/CVE-2024-10914-Exploit★ 0githubgithub.com/0xSS3K/CVE-2024-10914__POC★ 0cve_referencenetsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07?pvs=4no verificadovulncheckvulncheck.com/xdb/b8db8f5b4ea4no verificadovulncheckvulncheck.com/xdb/66ae016baa3bno verificadovulncheckvulncheck.com/xdb/44163f579aebno verificadovulncheckvulncheck.com/xdb/ad064f09887dno verificadovulncheckvulncheck.com/xdb/2eaa329a97ebno verificadovulncheckvulncheck.com/xdb/ee5eb809e894no verificadovulncheckvulncheck.com/xdb/72c78d52813cno verificadovulncheckvulncheck.com/xdb/7cf440e61333no verificadovulncheckvulncheck.com/xdb/9ce01a264ae3no verificadovulncheckvulncheck.com/xdb/ce1605f1f68bno verificadovulncheckvulncheck.com/xdb/5ffb03f6271ano verificadovulncheckvulncheck.com/xdb/111903db432eno verificadovulncheckvulncheck.com/xdb/439b7356b3e8no verificadovulncheckvulncheck.com/xdb/7217a9ad42e7no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07?pvs=4https://vuldb.com/?ctiid.283309https://vuldb.com/?id.283309https://vuldb.com/?submit.432847https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-flaw-affecting-60-000-older-nas-devices/https://www.dlink.com/