← Vulnerability feed

Vulnerability record · CVE-2024-3273 · published 4 April 2024

CVE-2024-3273: D-Link legacy NAS command injection in nas_sharing.cgi

Dlink · Dns 320l Firmware

An unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS models, where manipulation of the 'system' argument allows arbitrary command execution. The affected products are no longer supported by the vendor, so no fix will be issued and the hardware should be retired. Public exploit code exists and the flaw is listed in CISA KEV, making it a high-value target for opportunistic scanning and compromise.

9.8 CVSS 3.1 Critical CISA KEV since 11 Apr 2024 EPSS 100% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
20Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote command injection with public exploit code, CISA KEV listing, near-maximum EPSS, and no vendor fix because the products are end-of-life.

What it is

An unauthenticated command injection flaw exists in the HTTP GET request handler of /cgi-bin/nas_sharing.cgi on multiple end-of-life D-Link NAS models, where manipulation of the 'system' argument allows arbitrary command execution. The affected products are no longer supported by the vendor, so no fix will be issued and the hardware should be retired. Public exploit code exists and the flaw is listed in CISA KEV, making it a high-value target for opportunistic scanning and compromise.

Impact

A remote attacker can execute arbitrary commands on the device, typically with root privileges, leading to full device compromise, data theft, or use as a foothold into the network. Because the devices are EOL, there is no vendor remediation path.

Attack surface

The flaw is reachable over the network via HTTP GET requests to /cgi-bin/nas_sharing.cgi; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication or user interaction is required. Any internet-exposed or reachable instance of the affected NAS firmware is a candidate.

Exploitation

CVE-2024-3273 is in CISA KEV (added 2024-04-11) and has an EPSS 30-day probability of 0.99997, with public exploit code referenced in third-party advisories. Active exploitation in the wild has been reported.

What to do

  • Retire and replace affected end-of-life D-Link NAS devices per vendor guidance; no patch will be released.
  • Immediately remove any affected device from internet exposure and block inbound access to /cgi-bin/nas_sharing.cgi at the perimeter.
  • Isolate remaining legacy NAS devices on a segmented VLAN with strict egress and lateral-movement controls.
  • Monitor vendor and CISA KEV guidance for any updated retirement or replacement instructions.
  • If devices cannot be removed, restrict management and data access to trusted hosts only and log all HTTP requests to the CGI interface.

Detection

  • Alert on HTTP GET requests to /cgi-bin/nas_sharing.cgi, especially those containing shell metacharacters or the 'system' parameter.
  • Monitor for unexpected outbound connections or command-and-control traffic originating from NAS device IPs.
  • Review device logs and network flow data for anomalous process execution or file writes on affected NAS units.
  • Hunt for known exploit payload patterns from public PoCs against the nas_sharing.cgi endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-3273 to the Known Exploited Vulnerabilities catalog on 11 April 2024 as "D-Link Multiple NAS Devices Command Injection Vulnerability". Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions. Federal deadline 2 May 2024.

Affected products

20 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3273 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-3272D-Link NAS Devices Hard-Coded Credentials in nas_sharing.cgiD-Link DNS and DNR series NAS devices contain hard-coded credentials reachable through the HTTP GET handler in /cgi-bin/nas_sharing.cgi, where the 'u…KEVEPSS 98%analysed8.8CVE-2022-40799D-Link DNR-322L backup config command injectionThe 'Backup Config' function in D-Link DNR-322L firmware 2.60B15 and earlier fails to verify the integrity of downloaded code, allowing an authentica…KEVEPSS 34%analysed8.7CVE-2024-7832Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS…EPSS 2.1%8.7CVE-2024-7831Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L…EPSS 1.8%8.7CVE-2024-7829Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS…EPSS 1.8%8.7CVE-2024-7830Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L…EPSS 1.8%8.7CVE-2024-7828Dlink dns-120 firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW,…EPSS 16%7.4CVE-2026-5214Dlink dnr-202l firmware memory buffer overflow vulnerabilityA vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-3273), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.