EXPOSURES › CVE-2024-3272
CVE-2024-3272
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link NAS devices contain hard-coded credentials enabling authenticated command injection and remote code execution.
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L devices ship with hard-coded credentials that allow authenticated command injection, leading to remote, unauthorized code execution. This poses a severe supply-chain risk for CMMC environments as compromised NAS devices can serve as lateral movement vectors or initial access points for ransomware. D-Link's history of unpatched RCEs in consumer firmware makes this failure avoidable and indicative of a critical security posture gap.
Shame score — Hard-coded credentials enabling authenticated RCE in widely deployed NAS devices is a negligent, avoidable failure that directly undermines CMMC supply-chain security controls.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.