CVE-2024-10914
D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account_mgr.cgi cgi_user_add os command injection
Description
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
In plain language
AI Act nowThis D-Link network storage/router firmware flaw can let an attacker run harmful commands on the device remotely if they can reach its management interface—small businesses should treat it as urgent because it’s been publicized and the fix depends on installing the vendor’s updates for your exact model.
CVE-2024-10914 is an OS command injection in D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L account management (cgi_user_add in /cgi-bin/account_mgr.cgi), triggered by manipulation of the request parameters and exploitable remotely; patch availability depends on installing the vendor’s firmware updates up to 20241028.
What to do now
- Check your D-Link model (DNS-320, DNS-320LW, DNS-325, or DNS-340L) and confirm you’re running a firmware version that is at or before 20241028.
- Verify whether the device’s web management/account features are reachable from the internet (for example, via remote access or port forwarding).
- If the device is reachable from the internet, immediately restrict it (remove port forwarding / VPN-gate access) while you update.
- Install the latest D-Link firmware update for your exact model from a trusted source, so you’re beyond the vulnerable release (i.e., later than the fix point 20241028).
- After updating, re-check remote reachability and monitor the device for unusual logins or user/account changes.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-10914 and every CVE in our database. Create a free account — no credit card required.
Create Free Account