Vulnerability record · CVE-2024-3273 · published 4 April 2024
CVE-2024-3273: D-Link legacy NAS command injection in nas_sharing.cgi
Dlink · Dns 320l Firmware
An unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS models, where manipulation of the 'system' argument allows arbitrary command execution. The affected products are no longer supported by the vendor, so no fix will be issued and the hardware should be retired. Public exploit code exists and the flaw is listed in CISA KEV, making it a high-value target for opportunistic scanning and compromise.
Description
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command injection with public exploit code, CISA KEV listing, near-maximum EPSS, and no vendor fix because the products are end-of-life.
What it is
An unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS models, where manipulation of the 'system' argument allows arbitrary command execution. The affected products are no longer supported by the vendor, so no fix will be issued and the hardware should be retired. Public exploit code exists and the flaw is listed in CISA KEV, making it a high-value target for opportunistic scanning and compromise.
Impact
A remote attacker can execute arbitrary commands on the device, typically with root privileges, leading to full device compromise, data theft, or use as a foothold into the network. Because the devices are EOL, there is no vendor remediation path.
Attack surface
The flaw is reachable over the network via HTTP GET requests to /cgi-bin/nas_sharing.cgi; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication or user interaction is required. Any internet-exposed or reachable instance of the affected NAS firmware is a candidate.
Exploitation
CVE-2024-3273 is in CISA KEV (added 2024-04-11) and has an EPSS 30-day probability of 0.99997, with public exploit code referenced in third-party advisories. Active exploitation in the wild has been reported.
What to do
- Retire and replace affected end-of-life D-Link NAS devices per vendor guidance; no patch will be released.
- Immediately remove any affected device from internet exposure and block inbound access to /cgi-bin/nas_sharing.cgi at the perimeter.
- Isolate remaining legacy NAS devices on a segmented VLAN with strict egress and lateral-movement controls.
- Monitor vendor and CISA KEV guidance for any updated retirement or replacement instructions.
- If devices cannot be removed, restrict management and data access to trusted hosts only and log all HTTP requests to the CGI interface.
Detection
- Alert on HTTP GET requests to /cgi-bin/nas_sharing.cgi, especially those containing shell metacharacters or the 'system' parameter.
- Monitor for unexpected outbound connections or command-and-control traffic originating from NAS device IPs.
- Review device logs and network flow data for anomalous process execution or file writes on affected NAS units.
- Hunt for known exploit payload patterns from public PoCs against the nas_sharing.cgi endpoint.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-3273 to the Known Exploited Vulnerabilities catalog on 11 April 2024 as "D-Link Multiple NAS Devices Command Injection Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 2 May 2024.
Affected products
20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/netsecfish/dlink | ExploitThird Party Advisory |
| https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 | Vendor Advisory |
| https://vuldb.com/?ctiid.259284 | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.259284 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.304661 | Third Party AdvisoryVDB Entry |
| https://github.com/netsecfish/dlink | ExploitThird Party Advisory |
| https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 | Vendor Advisory |
| https://vuldb.com/?ctiid.259284 | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.259284 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.304661 | Third Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-3273 | US Government Resource |
| https://www.greynoise.io/blog/cve-2024-3273-d-link-nas-rce-exploited-in-the-wild | Third Party Advisory |
Track CVE-2024-3273 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-3273), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.