CVE-2024-10914: D-Link NAS – Command Injection via Name Parameter

CVE-2024-10914: D-Link NAS - Command Injection via Name Parameter-渗透云记 - 专注于网络安全与技术分享
CVE-2024-10914: D-Link NAS – Command Injection via Name Parameter
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-10914: D-Link NAS – Command Injection via Name Parameter

漏洞描述

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享