CVE-2024-8212

MEDIUM EPSS 93.7%
Published Aug 27, 20241y ago · Modified Jun 17, 20261w ago
5.3 CVSS 4.0
Medium
Find Similar
Published Aug 27, 2024 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been rated as critical. This issue affects the function cgi_FMT_R12R5_2nd_DiskMGR of the file /cgi-bin/hd_config.cgi. The manipulation of the argument f_source_dev leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

CVSS Details

Base Score
5.3
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
93.7% percentile
Exploit & Patch Status
Public Exploit Known
No Patch Available

Weaknesses 1

CWE-77 Command Injection Injection

Affected Products 40

VendorProductVersionRange
dlinkdns-315l_firmware*any
dlinkdns-315l*any
dlinkdns-320lw_firmware*any
dlinkdns-320lw*any
dlinkdns-1550-04_firmware*any
dlinkdns-1550-04*any
dlinkdns-1200-05_firmware*any
dlinkdns-1200-05*any
dlinkdns-1100-4_firmware*any
dlinkdns-1100-4*any
dlinkdns-726-4_firmware*any
dlinkdns-726-4*any
dlinkdns-345_firmware*any
dlinkdns-345*any
dlinkdns-343_firmware*any
dlinkdns-343*any
dlinkdns-340l_firmware*any
dlinkdns-340l*any
dlinkdnr-326_firmware*any
dlinkdnr-326*any
dlinkdns-327l_firmware*any
dlinkdns-327l*any
dlinkdns-326_firmware*any
dlinkdns-326*any
dlinkdns-325_firmware*any
dlinkdns-325*any
dlinkdns-323_firmware*any
dlinkdns-323*any
dlinkdnr-322l_firmware*any
dlinkdnr-322l*any
dlinkdns-321_firmware*any
dlinkdns-321*any
dlinkdns-320l_firmware*any
dlinkdns-320l*any
dlinkdns-320_firmware*any
dlinkdns-320*any
dlinkdnr-202l_firmware*any
dlinkdnr-202l*any
dlinkdns-120_firmware*any
dlinkdns-120*any

References 6

  • github.com https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_FMT_R12R5_2nd_DiskMGR.md
    ExploitThird Party Advisory
  • supportannouncement.us.dlink.com https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383
    Vendor Advisory
  • vuldb.com https://vuldb.com/?ctiid.275921
    Permissions Required
  • vuldb.com https://vuldb.com/?id.275921
    Third Party Advisory
  • vuldb.com https://vuldb.com/?submit.397276
    Third Party Advisory
  • dlink.com https://www.dlink.com/
    Product

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.