• News/
  • https://www.bleepingcomputer.com/news/security/critical-rce-bug-in-92-000-d-link-nas-devices-now-exploited-in-attacks/

Critical RCE bug in 92,000 D-Link NAS devices now exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Apr 8, 2024
·
Updated

Image: Midjourney ​Attackers are now actively targeting over 92,000 end-of-life D-Link Network Attached Storage (NAS) devices exposed online and unpatched against a critical remote code execution (RCE) zero-day flaw. As BleepingComputer first reported on Saturday, this security vulnerability (CVE-2024-3273) is the result of a backdoor facilitated through a hardcoded account (username "messagebus" with an empty password) and a command injection issue via the "system" parameter. Threat actors are now chaining these two security flaws to deploy a variant of the Mirai malware (skid.x86). Mirai variants are usually designed to add infected devices to a botnet that can be used in large-scale distributed denial-of-service (DDoS) attacks. These attacks started on Monday, as observed by cybersecurity firm GreyNoise and threat monitoring platform ShadowServer. Two weeks earlier, security researcher Netsecfish disclosed the vulnerability after D-Link informed them that these end-of-life devices would not be patched. "The described vulnerability affects multiple D-Link NAS devices, including models DNS-340L, DNS-320L, DNS-327L, and DNS-325, among others," Netsecfish explains. "Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the system, potentially leading to unauthorized access to sensitive information, modification of system configurations, or denial of service conditions." ​When asked whether security updates would be released to ...

Read full article

Affected Software

5 affected components
D-Link Network Attached Storage (NAS)
D-Link DNS-340L
D-Link DNS-320L
D-Link DNS-327L
D-Link DNS-325
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution (RCE) vulnerability in over 92,000 unpatched D-Link NAS devices that are currently being exploited in attacks.

2

What security implications are discussed in the article?

The article highlights the risks associated with the zero-day RCE vulnerability, which allows attackers to execute arbitrary code on vulnerable D-Link NAS devices.

3

What products are mentioned as being affected by this vulnerability?

The affected products include several D-Link Network Attached Storage (NAS) models such as DNS-340L, DNS-320L, DNS-327L, and DNS-325.

4

What is the status of these D-Link devices regarding updates?

The devices affected by this vulnerability are classified as end-of-life and are not receiving security patches from D-Link.

5

How many devices are exposed to this vulnerability?

Over 92,000 D-Link NAS devices are reported to be exposed online and unpatched against the critical RCE vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203