RULE(RULE ID:338185)

Rule General Information
Release Date: 2024-07-02
Rule Name: D-Link nas_sharing.cgi Remote Code Execution Vulnerability (CVE-2024-3273)
Severity:
CVE ID:
Rule Protection Details
Description: D-Link Network Storage (NAS) is a router from the Chinese company D-link. The D-Link NAS nas_sharing.cgi interface has a remote code execution vulnerability in the /cgi-bin/nas_sharing.cgi program. The vulnerability is caused by a backdoor through a hard-coded account (username: messagebus and empty password) and command injection through the system parameter. An unauthenticated attacker could exploit this vulnerability to gain access to the server.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: https://github.com/netsecfish/dlink
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383
https://vuldb.com/?ctiid.259284
https://vuldb.com/?id.259284
Solutions
Please contact the software vendor to update the software patch.