CVE-2024-7832 is a critical buffer overflow vulnerability affecting numerous D-Link DNS and DNR series network-attached storage (NAS) devices, specifically within the cgi_get_fullscreen_photos function of the /cgi-bin/photocenter_mgr.cgi file. This flaw, stemming from improper handling of the 'user' argument, allows for remote code execution. With a CVSS score of 8.8 (High), the vulnerability can be exploited remotely with low attack complexity and requires only low privileges, potentially leading to high impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is no evidence of active exploitation in the wild, nor are there Metasploit or Nuclei modules available. Community discussion and media coverage for this CVE are minimal, consistent with typical patterns for many vulnerabilities. It is crucial to note that all affected products are end-of-life and unsupported by the vendor, necessitating their immediate retirement and replacement.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-120_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dnr-202l_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-315l_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-320_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dns-320l_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.