A threat researcher has disclosed a new arbitrary command injection and hardcoded backdoor flaw in multiple end-of-life D-Link Network Attached Storage (NAS) device models. The researcher who discovered the flaw, 'Netsecfish,' explains that the issue resides within the'/cgi-bin/nas_sharing.cgi' script, impacting its HTTP GET Request Handler component. The two main issues contributing to the flaw, tracked as CVE-2024-3273, are a backdoor facilitated through a hardcoded account (username: "messagebus" and empty password) and a command injection problem via the "system" parameter. When chained together, any attacker can remotely execute commands on the device. The command injection flaw arises from adding a base64-encoded command to the "system" parameter via an HTTP GET request, which is then executed. "Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the system, potentially leading to unauthorized access to sensitive information, modification of system configurations, or denial of service conditions," warns the researcher. The device models impacted by CVE-2024-3273 are: Netsecfish says network scans show over 92,000 vulnerable D-Link NAS devices exposed online and susceptible to attacks through these flaws. After contacting D-Link about the flaw and whether a patch would be released, the vendor told us that these NAS devices had reached the end of life (EOL) and are no longer supported. "All D-Link Network Attached storag...
Over 92,000 exposed D-Link NAS devices have a backdoor account
BleepingComputer
·Bill Toulas
·Published Apr 6, 2024
·Updated
Affected Software
1 affected component
D-Link Network Attached Storage (NAS) device models
Frequently Asked Questions
1
What is the main issue reported in the article?
The article reports the discovery of a backdoor account and arbitrary command injection vulnerability in over 92,000 exposed D-Link NAS devices.
2
What specific D-Link products are impacted by these vulnerabilities?
The vulnerabilities affect multiple end-of-life D-Link Network Attached Storage (NAS) device models.
3
Who discovered the security flaw in the D-Link devices?
The security flaw was discovered by a threat researcher known as 'Netsecfish'.
4
What security risks are associated with the exposed D-Link NAS devices?
The exposed devices could allow unauthorized access and control, leading to potential data breaches and system compromise.
5
Are there any remediation steps suggested for affected D-Link NAS users?
The article does not provide specific remediation steps, but users are generally advised to secure their devices and consider disabling remote access features.