CVE-2024-8127 is a critical command injection vulnerability affecting numerous D-Link DNS and DNR series network-attached storage (NAS) devices, specifically within the cgi_unzip function of the /cgi-bin/webfile_mgr.cgi component. This flaw allows an unauthenticated, remote attacker to execute arbitrary commands on the affected device by manipulating the 'path' argument in an HTTP POST request. With a CVSS score of 9.8 (Critical), successful exploitation grants full compromise of confidentiality, integrity, and availability. While the vulnerability is publicly disclosed and exploit code is available, it primarily impacts end-of-life products that D-Link no longer supports, and there is no evidence of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-1550-04_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-1200-05_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-1100-4_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-726-4_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-345_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.