CVE-2024-3272: D-Link Network Attached Storage – Backdoor Account

CVE-2024-3272: D-Link Network Attached Storage - Backdoor Account-渗透云记 - 专注于网络安全与技术分享
CVE-2024-3272: D-Link Network Attached Storage – Backdoor Account
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-3272: D-Link Network Attached Storage – Backdoor Account

漏洞描述

A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享