CVE-2024-8133: D-Link DNS-1550-04 HTTP POST Request hd_config.cgi cgi_FMT_R5_SpareDsk_DiskMGR command injection
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been declared as critical. This vulnerability affects the function cgiFMTR5SpareDskDiskMGR of the file /cgi-bin/hdconfig.cgi of the component HTTP POST Request Handler. The manipulation of the argument fsourcedev leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8133?
CVE-2024-8133 has been declared as critical due to its potential to allow unauthorized access to affected D-Link devices.
How do I fix CVE-2024-8133?
To fix CVE-2024-8133, users should update their D-Link devices to the latest firmware version released after August 14, 2024.
Which D-Link devices are affected by CVE-2024-8133?
CVE-2024-8133 affects various D-Link models including DNS-120, DNS-320, and DNR-202L among others.
What are the risks associated with CVE-2024-8133?
The risks include unauthorized access to sensitive data and potential control over the affected devices.
Is there a workaround for CVE-2024-8133?
Currently, there are no recommended workarounds for CVE-2024-8133 other than updating to the fixed firmware.