CVE-2024-8132 is a critical command injection vulnerability affecting numerous D-Link DNS and DNR series network-attached storage (NAS) devices, specifically within the webdav_mgr function of the /cgi-bin/webdav_mgr.cgi component. An unauthenticated remote attacker can exploit this by manipulating the f_path argument in an HTTP POST request, leading to full compromise of the affected device. Despite public disclosure of the exploit, the vendor has confirmed these products are end-of-life and unsupported, urging immediate replacement. While no active exploitation or exploit frameworks are publicly listed, its high CVSS score of 9.8 and EPSS percentile indicate a significant risk, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-1550-04_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-1200-05_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-1100-4_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-726-4_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-345_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.