CVE-2024-8131: D-Link DNS-1550-04 HTTP POST Request apkg_mgr.cgi module_enable_disable command injection
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function moduleenabledisable of the file /cgi-bin/apkgmgr.cgi of the component HTTP POST Request Handler. The manipulation of the argument fmodulename leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8131?
CVE-2024-8131 is classified as a critical vulnerability.
Which D-Link devices are affected by CVE-2024-8131?
CVE-2024-8131 affects multiple D-Link models including DNS-120, DNR-202L, and DNS-1550-04 among others.
How do I fix CVE-2024-8131?
To mitigate CVE-2024-8131, update the affected D-Link device to the latest firmware version.
Can CVE-2024-8131 lead to unauthorized access?
Yes, CVE-2024-8131 could potentially allow attackers to gain unauthorized access to vulnerable systems.
Is there a specific firmware version to apply for CVE-2024-8131?
Check for the latest firmware released by D-Link for your specific model to address CVE-2024-8131.