Skip to content
COOEY

EXPOSURES › CVE-2024-3272

CVE-2024-3272

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-04-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-3272 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildhardcoded-credssupply-chain

D-Link NAS devices contain hard-coded credentials enabling authenticated command injection and remote code execution.

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L devices ship with hard-coded credentials that allow authenticated command injection, leading to remote, unauthorized code execution. This poses a severe supply-chain risk for CMMC environments as compromised NAS devices can serve as lateral movement vectors or initial access points for ransomware. D-Link's history of unpatched RCEs in consumer firmware makes this failure avoidable and indicative of a critical security posture gap.

Shame score — Hard-coded credentials enabling authenticated RCE in widely deployed NAS devices is a negligent, avoidable failure that directly undermines CMMC supply-chain security controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.