QID 731365
Date Published: 2024-04-11
QID 731365: D-Link NAS Storage Devices Remote Code Execution (RCE) Vulnerability
This vulnerability impacts various D-Link NAS (Network Attached Storage) devices such as the DNS-340L, DNS-320L, DNS-327L, and DNS-325. The vulnerability lies within the nas_sharing.cgi uri, which is vulnerable due to two main issues: a backdoor facilitated by hardcoded credentials, and a command injection vulnerability via the system parameter.
Affected Devices:
All Versions of DNS-320L
All Versions of DNS-325
All Versions of DNS-327L
All Versions of DNS-340L
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable D-Link NAS devices by sending a crafted payload as an HTTP GET request to the 'cgi-bin/nas_sharing.cgi' endpoint and checks for code execution.
Successful exploitation of the vulnerability may allow a remote unauthenticated attacker to execute arbitrary code, leading to critical data loss and possible system compromise.
- D-Link Security Advisory -
supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383
CVEs related to QID 731365
| Advisory ID | Software | Component | Link |
|---|