CVE-2024-8134: D-Link DNS-1550-04 HTTP POST Request hd_config.cgi cgi_FMT_Std2R5_1st_DiskMGR command injection
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been rated as critical. This issue affects the function cgiFMTStd2R51stDiskMGR of the file /cgi-bin/hdconfig.cgi of the component HTTP POST Request Handler. The manipulation of the argument fsourcedev leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8134?
CVE-2024-8134 has been rated as critical.
Which D-Link devices are affected by CVE-2024-8134?
CVE-2024-8134 affects various D-Link models including the DNS-120, DNS-320, and DNS-1550 among others.
How do I fix CVE-2024-8134?
To mitigate CVE-2024-8134, update the firmware of the affected D-Link devices to the latest version available.
Is CVE-2024-8134 exploitable remotely?
Yes, CVE-2024-8134 is considered potentially exploitable remotely.
What should I do if I cannot update my D-Link device to fix CVE-2024-8134?
If you cannot update, consider isolating the device from public network access and implementing strict firewall rules.