A significant security vulnerability has been identified in several older D-Link network-attached storage (NAS) devices, posing a serious threat to users still utilizing these outdated models. This flaw, officially cataloged as CVE-2024-10914 in the National Vulnerability Database, carries a critical severity score of 9.2, indicating the high potential risk associated with it.
The vulnerability is rooted in the ‘cgi_user_add’ command, specifically involving the ‘name’ parameter, which fails to properly sanitize input. This allows attackers to exploit the weakness without the need for authentication, thus enabling the injection of harmful shell commands through tailored HTTP GET requests.
The D-Link models affected by this flaw are the DNS-320 Version 1.00, DNS-320LW Version 1.01.0914.2012, DNS-325 Versions 1.01 and 1.02, and DNS-340L Version 1.08. A scan by security researcher Netsecfish revealed over 61,000 instances of these vulnerable devices, with more than 41,000 unique IP addresses identified. Although the National Vulnerability Database suggests that exploiting this flaw requires advanced skills, the risk remains for those devices exposed to the internet.
Unfortunately, D-Link has decided against releasing a patch for this issue, as these models have been deemed end-of-life/end-of-service since 2020. In their statement, D-Link advises users to retire or replace these devices since no future updates or security patches will be forthcoming.
For users unable to immediately replace their vulnerable devices, security experts recommend several temporary protective measures. The primary suggestion is to remove these devices from public internet exposure to reduce the risk of exploitation. Further, implementing rigorous access controls—restricting device access to trusted IP addresses and authorized users only—can help manage potential threats. Some experts also propose considering third-party firmware updates, albeit only from reputable and verified sources. Nonetheless, these precautions should be seen as temporary, with users encouraged to arrange for a permanent replacement of their affected NAS devices swiftly.






