CVE-2024-8210: D-Link DNS-1550-04 hd_config.cgi sprintf command injection
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. It has been classified as critical. This affects the function sprintf of the file /cgi-bin/hdconfig.cgi. The manipulation of the argument fmount leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8210?
CVE-2024-8210 has been classified as critical, indicating a high risk of exploitation.
How do I fix CVE-2024-8210?
To fix CVE-2024-8210, update your affected D-Link device to the latest firmware version available from D-Link.
Which D-Link products are affected by CVE-2024-8210?
CVE-2024-8210 affects various D-Link NAS devices including DNS-120, DNS-315L, DNS-320, and others listed in the vulnerability report.
Is CVE-2024-8210 being actively exploited?
There are indications that CVE-2024-8210 may be actively exploited, emphasizing the need for immediate remediation.
What type of vulnerability is CVE-2024-8210?
CVE-2024-8210 is a critical vulnerability that can potentially allow unauthorized access to sensitive data on affected D-Link devices.