CVE-2024-7828 is a critical buffer overflow vulnerability (CWE-120) found in the cgi_set_cover function of /cgi-bin/photocenter_mgr.cgi across numerous D-Link DNS and DNR series devices. This flaw, triggered by manipulating the album_name argument, allows for remote exploitation without authentication. With a CVSS score of 9.8 (Critical), successful exploitation could lead to complete compromise of confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion. D-Link has confirmed these affected products are End-of-Life and unsupported, recommending their immediate retirement and replacement.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-120_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dnr-202l_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-315l_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-320_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-320l_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.