EXPOSURES › CVE-2024-3273
CVE-2024-3273
HIGH ⌖ ON CISA KEV · EXPLOITEDD-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L) have a command injection vulnerability that enables remote code execution when combined with CVE-2024-3272.
This vulnerability allows remote, unauthorized code execution on D-Link NAS devices, posing a severe supply chain risk for CMMC environments that rely on these devices for data storage. D-Link's history of repeated RCE and command injection flaws in consumer firmware makes this a high-priority failure for defense contractors to audit and mitigate.
Shame score — D-Link's repeated history of unpatched RCE and command injection vulnerabilities in consumer firmware, combined with active exploitation, creates a high embarrassment score due to the avoidable nature of the risk and the vendor's poor security track record.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.