← Vulnerability feed

Vulnerability record · CVE-2024-3272 · published 4 April 2024

CVE-2024-3272: D-Link NAS Devices Hard-Coded Credentials in nas_sharing.cgi

Dlink · Dns 320l Firmware

D-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'user' argument accepts the value 'messagebus'. The flaw is rated CVSS 9.8 and affects products that are end-of-life and no longer supported by the vendor. Because the credentials are fixed and publicly documented, any reachable device is effectively open to unauthenticated compromise.

9.8 CVSS 3.1 Critical CISA KEV since 11 Apr 2024 EPSS 98% · top 0.1% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score, v2 10.0
98%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
20Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing, near-certain EPSS score and a public exploit against unsupported devices with no vendor patch make this an immediate remediation priority.

What it is

D-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'user' argument accepts the value 'messagebus'. The flaw is rated CVSS 9.8 and affects products that are end-of-life and no longer supported by the vendor. Because the credentials are fixed and publicly documented, any reachable device is effectively open to unauthenticated compromise.

Impact

An attacker gains unauthenticated remote access to the device with the privileges tied to the hard-coded account, enabling full compromise of confidentiality, integrity and availability. On a NAS this typically means access to stored data and the ability to alter device behavior.

Attack surface

Reachable over the network via HTTP GET requests to /cgi-bin/nas_sharing.cgi; the CVSS vector shows no privileges and no user interaction required. Any device exposing this CGI endpoint to an untrusted network is exposed.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-04-11, and EPSS gives a 30-day exploitation probability of 0.98038 (99.9th percentile). A public exploit is referenced, so active exploitation should be assumed.

What to do

  • Retire and replace affected end-of-life D-Link DNS/DNR devices; the vendor states no fix will be provided.
  • If retirement is not immediate, remove the devices from internet exposure and restrict management and CGI access to a trusted internal network only.
  • Block or filter access to /cgi-bin/nas_sharing.cgi at the network perimeter and on internal segmentation boundaries.
  • Monitor vendor advisory SAP10383 for any updated guidance and track CISA KEV remediation deadlines.
  • Inventory all listed DNS and DNR models on the network so unmanaged units are not overlooked.

Detection

  • Search web/proxy logs for GET requests to /cgi-bin/nas_sharing.cgi, especially with a user parameter value of messagebus.
  • Alert on inbound connections to NAS management or CGI ports from outside expected internal ranges.
  • Monitor for authentication or configuration changes on D-Link NAS devices that do not correspond to known administrative activity.
  • Use network discovery to flag any of the affected DNS/DNR models still responding on the network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-3272 to the Known Exploited Vulnerabilities catalog on 11 April 2024 as "D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 2 May 2024.

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3272 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-3273D-Link legacy NAS command injection in nas_sharing.cgiAn unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS model…KEVEPSS 100%analysed8.8CVE-2022-40799D-Link DNR-322L backup config command injectionThe 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authentica…KEVEPSS 34%analysed8.7CVE-2024-7832Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS…EPSS 2.1%8.7CVE-2024-7831Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L…EPSS 1.8%8.7CVE-2024-7829Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS…EPSS 1.8%8.7CVE-2024-7830Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L…EPSS 1.8%8.7CVE-2024-7828Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,…EPSS 16%7.4CVE-2026-5214Dlink dnr-202l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-3272), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.