Vulnerability threat dossier

CVE-2024-3273

dlinkdnr-202l

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

VTP deterministic threat59.5of 100 · CVSS excluded

VTP analyst assessment

D-Link NAS command injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence88%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this command-injection vulnerability in multiple D-Link NAS devices as exploited globally. The nas_sharing.cgi HTTP GET handler can process a manipulated system argument, and public exploit tooling coverage is reported.

Why it matters

  • A remotely reachable NAS web interface creates an opportunity for command injection.
  • The affected devices were unsupported when assigned, increasing the need for containment or replacement.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The tooling record does not establish successful exploitation or reliable execution.

The available records do not identify a supported update.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use the affected D-Link NAS models, remove their management interfaces from internet exposure and restrict access.

AI baseline history (2)
  1. BASELINE ASSESSED
    D-Link NAS command injectiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    D-Link NAS command injectiongpt-5.6-sol · high
Technical severityHIGHCVSS 7.3 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:a26a099aaa6af77efac5e25c1d6e737ef4a20a97ACTIVE
04

Event history

Threat timeline

  1. 02:3215 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 11:1031 Mar
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2024-3273.

  3. 00:0011 Apr
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 23 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 23 CVEs in this pinned revision. 23 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2022-45440CVE-2023-28769CVE-2023-28770CVE-2024-3272CVE-2024-3273CVE-2024-3274CVE-2024-7715CVE-2024-7828CVE-2024-7829CVE-2024-7830CVE-2024-7831CVE-2024-7832CVE-2024-7849CVE-2024-7922CVE-2024-8127CVE-2024-8128CVE-2024-8129CVE-2024-8130CVE-2024-8131CVE-2024-8132CVE-2024-8133CVE-2024-8134CVE-2024-8461
Separate evidence group

Nuclei Templates v10.4.1 – Release Notes

New Templates Added: 76 | CVEs Added: 42 | First-time contributions: 10 🔥 Release Highlights 🔥 [ CVE-2026-32596 ] Glances - Information Disclosure ( @theamanrawat ) [high] 🔥 [CVE-2026-31816] Budibase - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-27483 ] MindsDB - Remote Code Execution ( @thewhiteh4t ) [high] 🔥 [CVE-2026-24477] AnythingLLM - Information Disclosure ( @dhiyaneshdk ) [high] 🔥 [ CVE-2026-22739 ] Spring Cloud Config Server - Path Traversal (@0x_Akoko, @vulnh0lic) [high] 🔥 [ CVE-2026-21445 ] Langflow - Broken Access Control ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-3055 ] Citrix NetScaler SAML IDP - Memory Overread ( @watchtowr , @shaikhyaser , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1581 ] wpForo Forum <= 2.4.14 - SQL Injection ( @Shivam Kamboj) [critical] (kev) (vKEV) 🔥 [ CVE-2025-71260 ] BMC FootPrints - Deserialization of Untrusted Data (RCE) ( @watchtowr , @dhiyaneshdk ) [critical] 🔥 [ CVE-2025-68043 ] LottieFiles WordPress Plugin <= 3.0.0 - Missing Authorization ( @pussycat0x ) [high] 🔥 [ CVE-2025-32463 ] Sudo - Local Privilege Escalation via chroot ( @SeungAh-Hong ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-14437 ] WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log File ( @pussycat0x ) [high] 🔥 [ CVE-2025-6984 ] langchain-ai langchain - XML External Entity Injection ( @nukunga ) [high] 🔥 [ CVE-2025-5947 ] Service Finder Bookings - Authentication Bypass ( @sedat4ras ) [critical] (kev) (vKEV) 🔥 [ CVE-2024-43144 ] Cost Calculator Builder <= 3.2.15 - SQL Injection ( @Shivam Kamboj) [critical] 🔥 [ CVE-2023-34092 ] Vite Dev Server - Information Exposure ( @ritikchaddha ) [high] 🔥 What's Changed Bug Fixes Fixed invalid hostname generation affecting template execution (PR #15641 , Issue #15624 ). Fixed extractor DSL by adding a missing condition (PR #15729 ). Moved CVE-2026-23829 from http to the correct network folder (PR #15738 , Issue #15633 ). Fixed reference URLs in CVE-2025-66516 (PR #15646 ). False Negatives Improved detection in FTP Service - Credential Weakness template, reducing underreporting (PR #15726 , Issue #15681 ). Addressed false negative in CVE-2024-3273 detection (Issue #15654 ). Addressed false negative in CVE-2021-25032 detection (Issue #13647 ). False Positives Reduced false positives and improved accuracy in the following templates: CVE-2025-71243 — excluded pages that echo back user input (PR #15665 ). CVE-2025-66516 — tightened matcher logic (PR #15581 ). CVE-2023-5652 (PR #15622 ). CVE-2023-7337 (PR #15620 ). CVE-2022-21587 — added matchers-condition: and (PR #15621 ). CVE-2009-1872 ColdFusion fingerprint (PR #15601 ). CVE-2002-1131 SquirrelMail fingerprint (PR #15595 ). CVE-2021-35042 (Issue #15241 ). flexnet-operations-panel — reduced high false positive rate (PR #15600 ). mercurial-hgignore — added text/xml and <?xml to negative matchers (PR #15623 ). aws-bucket-takeover — excluded S3 account regional namespace buckets (PR #15608 ). hubspot-takeover — switched to header-based detection for NotFoundResolver (PR #15583 ). Enhancements Enriched classification metadata and renamed CVE-2020-15718 (PR #15677 ). Updated classification metadata for CVE-2024-55550 (PR #15666 ). Updated classification metadata for CVE-2024-13726 (PR #15648 ). Updated apache-activemq-artemis-detect.yaml detection logic (PR #15717 ). Applied AI-assisted tagging improvements across multiple templates (PR #15571 ). Templates Added [CVE-2026-33868] Mastodon - Open Redirect ( @theamanrawat ) [medium] 🔥 [ CVE-2026-32596 ] Glances - Information Disclosure ( @theamanrawat ) [high] 🔥 [ CVE-2026-32583 ] Webnus Inc. Modern Events Calendar - Broken Access Control ( @theamanrawat ) [medium] 🔥 [CVE-2026-31816] Budibase - Authentication Bypass ( @theamanrawat ) [critical] 🔥 [ CVE-2026-30928 ] Glances - Information Disclosure ( @theamanrawat ) [high] 🔥 [CVE-2026-28288] Dify User Enumeration via Observable Response Discrepancy ( @dhiyaneshdk ) [medium] 🔥 [ CVE-2026-27483

CVE-2002-1131CVE-2009-1872CVE-2020-15718CVE-2021-25032CVE-2021-35042CVE-2022-1692CVE-2022-21587CVE-2023-34092CVE-2023-5652CVE-2023-7337CVE-2024-13726CVE-2024-3273CVE-2024-43144CVE-2024-55550CVE-2024-57241CVE-2025-13920CVE-2025-14437CVE-2025-32463CVE-2025-4576CVE-2025-46565CVE-2025-54793CVE-2025-58044CVE-2025-5947CVE-2025-59716CVE-2025-62126CVE-2025-62512CVE-2025-66516CVE-2025-68043CVE-2025-68602CVE-2025-6984CVE-2025-71243CVE-2025-71257CVE-2025-71258CVE-2025-71259CVE-2025-71260CVE-2026-0926CVE-2026-1277CVE-2026-1296CVE-2026-1306CVE-2026-1405CVE-2026-1557CVE-2026-1581CVE-2026-2025CVE-2026-21445CVE-2026-22739CVE-2026-23829CVE-2026-24477CVE-2026-27483CVE-2026-28288CVE-2026-3055CVE-2026-30928CVE-2026-31816CVE-2026-32583CVE-2026-32596CVE-2026-33868
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
7.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE
CWE-77
CPE records
43
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.