CVE-2024-8213: D-Link DNS-1550-04 hd_config.cgi cgi_FMT_R12R5_1st_DiskMGR command injection
A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. Affected is the function cgiFMTR12R51stDiskMGR of the file /cgi-bin/hdconfig.cgi. The manipulation of the argument fsourcedev leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8213?
CVE-2024-8213 is classified as a critical severity vulnerability.
How do I fix CVE-2024-8213?
To mitigate CVE-2024-8213, you should apply the latest firmware updates provided by D-Link for the affected devices.
Which D-Link products are affected by CVE-2024-8213?
CVE-2024-8213 affects several D-Link models, including DNS-120, DNS-320, DNR-202L, and many others.
What type of vulnerability is CVE-2024-8213?
CVE-2024-8213 is categorized as a critical vulnerability, indicating a potential serious impact on the affected systems.
Is there a workaround for CVE-2024-8213?
Currently, the recommended action for CVE-2024-8213 is to update to the latest firmware as there are no effective workarounds available.