CameraRisk

CVE-2024-3272

D-Link · exploited in the wild

Published
4 April 2024
Last modified
17 June 2026
CVSS
9.8 v3.1
Severity
critical
EPSS
98.0% (100th pct)
CISA KEV
Added 11 April 2024 KEV
NVD status
Analyzed
Weaknesses
CWE-798

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Exploitation

Added to the CISA Known Exploited Vulnerabilities catalogue on 11 April 2024, with a remediation due date of 2 May 2024 for US federal civilian agencies. CISA records no known ransomware campaign use.

Required action as published by CISA: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

Affected products

ProductVendorTypeVersions named
DNR-202L D-Link unknown <= 2026-02-05
DNR-322L D-Link unknown <= 2.60b15
DNR-326 D-Link unknown <= 1.40b03, <= 2026-02-05

References

Vendor advisory and patch

CVE-2024-3272 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.