FAIL › dossier
Multiple NAS Devices
PRODUCT· dossier confidence 50%
Recent high severity vulnerabilities highlight significant security gaps in D-Link's NAS devices, necessitating urgent attention to security posture and processes.
PROFILE
CategoryTechnologyWhat they doManufactures network-attached storage (NAS) devices.
SECURITY POSTURE
Needs improvement; recent high severity vulnerabilities indicate a lack of robust security practices.
Notable failures
- CVE-2024-3272
- CVE-2024-3273
Patterns: hard-coded credentials; remote code execution
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-04-11 | CVE-2024-3272 | high | D-Link NAS devices contain hard-coded credentials enabling authenticated command injection and remote code execution. |
| 2024-04-11 | CVE-2024-3273 | high | D-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L) have a command injection vulnerability that enables remote code execution when combined with CVE-2024-3272. |
Open questions: What steps has D-Link taken to address these vulnerabilities? · Are there any plans to update affected devices with patches?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-05 03:44:31.284079+00:00