LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-3273: D-Link Multiple NAS Devices Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 11, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 2, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-3273 to its Known Exploited Vulnerabilities catalog on Apr 11, 2024, with a federal patch deadline of May 2, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.

CVE-2024-3273 is a command injection vulnerability affecting certain D-Link network-attached storage (NAS) devices. It matters because, when combined with another related flaw, it can enable remote, unauthorized code execution on exposed systems that store and share files across a network. These are legacy products that have reached end-of-life, so the risk is ongoing for any remaining units still online.

IT and security teams should treat this as a high-priority inventory and retirement issue rather than a routine patch cycle. Public detail is limited to the models and weakness class listed by CISA; confirm all specifics against the vendor advisory and CISA guidance.

How it works

The vulnerability is classified as CWE-77, improper neutralization of special elements used in a command (command injection). In products of this class, user-supplied input that reaches a system command or shell is not properly sanitized. An attacker who can reach the vulnerable interface can inject additional commands that the device then executes with the privileges of the affected process.

According to the CISA summary, the flaw is present in D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L devices. When combined with CVE-2024-3272, the result can be remote, unauthorized code execution. Exact attack vectors, required authentication state, or payload formats are not provided in the available facts; treat any public exploit claims as unverified until confirmed against official advisories. Do not assume internet-facing exposure is required—internal network access may also be sufficient depending on configuration.

Am I affected? How to find it in your systems

These devices are typically deployed as small-business or home-office NAS units for file sharing, backups, and media storage. They often sit on local networks with optional remote-access features enabled.

If any of these models appear in your environment, treat them as affected until proven otherwise by the vendor advisory.

How to remediate

CISA’s required action is clear: these are legacy products that have reached end-of-life or end-of-service. All associated hardware revisions should be retired and replaced per vendor instructions. There is no ongoing patch stream for EOL devices, so applying a vendor update is not a viable long-term path.

Confirm the exact retirement guidance and any recommended migration steps against the vendor’s official EOL notices and the CISA advisory.

If you can't patch immediately

Because these products are EOL, “patching” is not available; the compensating controls below reduce exposure until replacement can be completed.

These measures lower risk but do not eliminate it. Prioritize replacement.

If your data may have been exposed

Actively exploited vulnerabilities on network storage devices can lead to data breaches, unauthorized access to files, or further lateral movement. Known ransomware use of this specific CVE is not documented in the available facts. If you believe these devices were reachable by untrusted parties, assume stored data and credentials may have been accessed. Review access logs, rotate any credentials that were stored or used on the NAS, and consider forensic imaging before powering the units down. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets as an additional indicator of compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedD-Link · Multiple NAS Devices
WeaknessCWE-77
Added to CISA KEVApr 11, 2024
Federal patch deadlineMay 2, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities