Image: Midjourney Attackers are now actively targeting over 92,000 end-of-life D-Link Network Attached Storage (NAS) devices exposed online and unpatched against a critical remote code execution (RCE) zero-day flaw. As BleepingComputer first reported on Saturday, this security vulnerability (CVE-2024-3273) is the result of a backdoor facilitated through a hardcoded account (username "messagebus" with an empty password) and a command injection issue via the "system" parameter. Threat actors are now chaining these two security flaws to deploy a variant of the Mirai malware (skid.x86). Mirai variants are usually designed to add infected devices to a botnet that can be used in large-scale distributed denial-of-service (DDoS) attacks. These attacks started on Monday, as observed by cybersecurity firm GreyNoise and threat monitoring platform ShadowServer. Two weeks earlier, security researcher Netsecfish disclosed the vulnerability after D-Link informed them that these end-of-life devices would not be patched. "The described vulnerability affects multiple D-Link NAS devices, including models DNS-340L, DNS-320L, DNS-327L, and DNS-325, among others," Netsecfish explains. "Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the system, potentially leading to unauthorized access to sensitive information, modification of system configurations, or denial of service conditions." When asked whether security updates would be released to ...
Critical RCE bug in 92,000 D-Link NAS devices now exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Apr 8, 2024
·Updated
Affected Software
5 affected components
D-Link Network Attached Storage (NAS)
D-Link DNS-340L
D-Link DNS-320L
D-Link DNS-327L
D-Link DNS-325
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical remote code execution (RCE) vulnerability in over 92,000 unpatched D-Link NAS devices that are currently being exploited in attacks.
2
What security implications are discussed in the article?
The article highlights the risks associated with the zero-day RCE vulnerability, which allows attackers to execute arbitrary code on vulnerable D-Link NAS devices.
3
What products are mentioned as being affected by this vulnerability?
The affected products include several D-Link Network Attached Storage (NAS) models such as DNS-340L, DNS-320L, DNS-327L, and DNS-325.
4
What is the status of these D-Link devices regarding updates?
The devices affected by this vulnerability are classified as end-of-life and are not receiving security patches from D-Link.
5
How many devices are exposed to this vulnerability?
Over 92,000 D-Link NAS devices are reported to be exposed online and unpatched against the critical RCE vulnerability.