Vulnerability record · CVE-2024-10915 · published 6 November 2024
CVE-2024-10915: D-Link DNS-320/325/340L NAS account_mgr.cgi OS command injection
Dlink · Dns 320 Firmware
The cgi_user_add function in /cgi-bin/account_mgr.cgi on D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L NAS devices fails to sanitize the group argument, allowing OS command injection. The flaw is rated critical (CVSS 4.0 9.2) and a public exploit exists, so unpatched NAS units exposed to a network are at serious risk.
Description
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCritical CVSS 9.2 command injection with a public exploit and very high EPSS, though high attack complexity and no KEV listing temper immediate mass-exploitation risk.
What it is
The cgi_user_add function in /cgi-bin/account_mgr.cgi on D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L NAS devices fails to sanitize the group argument, allowing OS command injection. The flaw is rated critical (CVSS 4.0 9.2) and a public exploit exists, so unpatched NAS units exposed to a network are at serious risk.
Impact
An attacker who can reach the CGI endpoint can execute arbitrary operating system commands on the NAS, gaining control of the device and any data or credentials it holds.
Attack surface
The endpoint is reachable over the network (AV:N) with no authentication or user interaction required per the CVSS vector, though the high attack complexity (AC:H) means exploitation requires specific conditions.
Exploitation
No CISA KEV listing and no ransomware association, but EPSS is 0.794 (99.6th percentile) and a public exploit reference is tagged, indicating active interest and available tooling.
What to do
- Apply the latest D-Link firmware for DNS-320, DNS-320LW, DNS-325 and DNS-340L; if no fix exists, retire or isolate the device.
- Remove internet exposure of the NAS management interface and restrict /cgi-bin/ access to trusted management networks only.
- Enforce authentication and network segmentation so the CGI endpoint is not reachable by untrusted clients.
- Monitor D-Link advisories and replace end-of-support NAS models with supported hardware.
Detection
- Inspect web server and CGI logs for requests to /cgi-bin/account_mgr.cgi with cmd=cgi_user_add and suspicious group parameter values containing shell metacharacters.
- Alert on unexpected child processes spawned by the web/CGI service (e.g., shell, wget, curl, nc) on the NAS.
- Monitor for outbound connections from NAS devices to unfamiliar hosts, which may indicate command-and-control or data exfiltration.
- Baseline normal account_mgr.cgi usage and flag anomalous group or user creation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://netsecfish.notion.site/Command-Injection-Vulnerability-in-group-parameter-for-D-Link-NAS-12d6b683e67c803fa1a0c0d | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.283310 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?id.283310 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.432848 | Third Party AdvisoryVDB Entry |
| https://www.dlink.com/ | Product |
Track CVE-2024-10915 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-10915), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.