Skip to content

CVE-2024-10914 D-Link Remote Code Execution (RCE)

Notifications You must be signed in to change notification settings

redspy-sec/D-Link

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2024-10914 D-Link Remote Code Execution (RCE)

D-Link NAS- Command Injection via Name Parameter CVE-2024-10914:-

A vulnerability was found in D-Link DNS-320, DNS- 320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_ado. The manipulation off the argument name leads to os command injection.

Dork FOFA: app="D_Link-DNS-ShareCenter"

About

CVE-2024-10914 D-Link Remote Code Execution (RCE)

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages