6Kas
CVE-2024-10914 | D-Link DNS-320/DNS-320LW/DNS-325/DNS-340L up to 20241028 account_mgr.cgi?cmd=cgi_user_add name os command injection
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the functioncgi_user_add
of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection.
This vulnerability is known as CVE-2024-10914. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.