Buaa1Otteam

#5479of 53,635
48.8Total CVSS
Vulnerabilities · 7
Medium
6
Critical
1
PT-2024-38818
6.5
2024-08-24
D Link · Dns-340L · CVE-2024-8129
Name of the Vulnerable Software and Affected Versions: D-Link DNS-120 up to 20240814 D-Link DNR-202L up to 20240814 D-Link DNS-315L up to 20240814 D-Link DNS-320 up to 20240814 D-Link DNS-320L up to 20240814 D-Link DNS-320LW up to 20240814 D-Link DNS-321 up to 20240814 D-Link DNR-322L up to 20240814 D-Link DNS-323 up to 20240814 D-Link DNS-325 up to 20240814 D-Link DNS-326 up to 20240814 D-Link DNS-327L up to 20240814 D-Link DNR-326 up to 20240814 D-Link DNS-340L up to 20240814 D-Link DNS-343 up to 20240814 D-Link DNS-345 up to 20240814 D-Link DNS-726-4 up to 20240814 D-Link DNS-1100-4 up to 20240814 D-Link DNS-1200-05 up to 20240814 D-Link DNS-1550-04 up to 20240814 Description: A critical vulnerability was found in the affected D-Link products. The issue affects the function `cgi s3 modify` of the file `/cgi-bin/s3.cgi` of the component HTTP POST Request Handler. The manipulation of the argument `f job name` leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Note that this vulnerability only affects products that are no longer supported by the maintainer, and the vendor has confirmed that the product is end-of-life. Recommendations: As a temporary workaround, consider disabling the `cgi s3 modify` function until a replacement product is installed. Restrict access to the `/cgi-bin/s3.cgi` file to minimize the risk of exploitation. Avoid using the `f job name` argument in the affected HTTP POST Request Handler until the issue is resolved. It is recommended to retire and replace the affected products as they are no longer supported by the maintainer. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-38822
6.5
2024-08-24
D Link · Dns-340L · CVE-2024-8133
Name of the Vulnerable Software and Affected Versions: D-Link DNS-120 up to 20240814 D-Link DNR-202L up to 20240814 D-Link DNS-315L up to 20240814 D-Link DNS-320 up to 20240814 D-Link DNS-320L up to 20240814 D-Link DNS-320LW up to 20240814 D-Link DNS-321 up to 20240814 D-Link DNR-322L up to 20240814 D-Link DNS-323 up to 20240814 D-Link DNS-325 up to 20240814 D-Link DNS-326 up to 20240814 D-Link DNS-327L up to 20240814 D-Link DNR-326 up to 20240814 D-Link DNS-340L up to 20240814 D-Link DNS-343 up to 20240814 D-Link DNS-345 up to 20240814 D-Link DNS-726-4 up to 20240814 D-Link DNS-1100-4 up to 20240814 D-Link DNS-1200-05 up to 20240814 D-Link DNS-1550-04 up to 20240814 Description: A critical vulnerability was found in the specified D-Link products. It affects the function `cgi FMT R5 SpareDsk DiskMGR` of the file `/cgi-bin/hd config.cgi` in the HTTP POST Request Handler component. The manipulation of the argument `f source dev` leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This issue only affects products that are no longer supported by the maintainer, and the vendor has confirmed that these products are end-of-life. Recommendations: As a temporary workaround, consider disabling the `cgi FMT R5 SpareDsk DiskMGR` function until a replacement is available. Restrict access to the `/cgi-bin/hd config.cgi` file to minimize the risk of exploitation. Avoid using the `f source dev` argument in the affected HTTP POST Request Handler until the issue is resolved. It is recommended to retire and replace the affected products as they are end-of-life. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-38823
6.5
2024-08-24
D Link · Dns-340L · CVE-2024-8134
Name of the Vulnerable Software and Affected Versions: D-Link DNS-120 up to 20240814 D-Link DNR-202L up to 20240814 D-Link DNS-315L up to 20240814 D-Link DNS-320 up to 20240814 D-Link DNS-320L up to 20240814 D-Link DNS-320LW up to 20240814 D-Link DNS-321 up to 20240814 D-Link DNR-322L up to 20240814 D-Link DNS-323 up to 20240814 D-Link DNS-325 up to 20240814 D-Link DNS-326 up to 20240814 D-Link DNS-327L up to 20240814 D-Link DNR-326 up to 20240814 D-Link DNS-340L up to 20240814 D-Link DNS-343 up to 20240814 D-Link DNS-345 up to 20240814 D-Link DNS-726-4 up to 20240814 D-Link DNS-1100-4 up to 20240814 D-Link DNS-1200-05 up to 20240814 D-Link DNS-1550-04 up to 20240814 Description: A critical issue affects the function `cgi FMT Std2R5 1st DiskMGR` of the file `/cgi-bin/hd config.cgi` in the component HTTP POST Request Handler. The manipulation of the argument `f source dev` leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This issue only affects products that are no longer supported by the maintainer, and the vendor has confirmed that the product is end-of-life. Recommendations: As a temporary workaround, consider disabling the `cgi FMT Std2R5 1st DiskMGR` function until a replacement is available. Restrict access to the `/cgi-bin/hd config.cgi` file to minimize the risk of exploitation. Avoid using the argument `f source dev` in the affected HTTP POST Request Handler until the issue is resolved. Retire and replace the affected products, as they are no longer supported by the maintainer.
PT-2024-38821
6.5
2024-08-24
D Link · D-Link Dns-1200-05 · CVE-2024-8132
Name of the Vulnerable Software and Affected Versions: D-Link DNS-120 up to 20240814 D-Link DNR-202L up to 20240814 D-Link DNS-315L up to 20240814 D-Link DNS-320 up to 20240814 D-Link DNS-320L up to 20240814 D-Link DNS-320LW up to 20240814 D-Link DNS-321 up to 20240814 D-Link DNR-322L up to 20240814 D-Link DNS-323 up to 20240814 D-Link DNS-325 up to 20240814 D-Link DNS-326 up to 20240814 D-Link DNS-327L up to 20240814 D-Link DNR-326 up to 20240814 D-Link DNS-340L up to 20240814 D-Link DNS-343 up to 20240814 D-Link DNS-345 up to 20240814 D-Link DNS-726-4 up to 20240814 D-Link DNS-1100-4 up to 20240814 D-Link DNS-1200-05 up to 20240814 D-Link DNS-1550-04 up to 20240814 Description: A critical vulnerability was found in the specified D-Link products. This issue affects the `webdav mgr` function of the `/cgi-bin/webdav mgr.cgi` file in the HTTP POST Request Handler component. The manipulation of the `f path` argument leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Note that this vulnerability only affects products that are no longer supported by the maintainer, and the vendor has confirmed that the product is end-of-life. Recommendations: As a temporary workaround, consider disabling the `webdav mgr` function until a replacement is available. Restrict access to the `/cgi-bin/webdav mgr.cgi` file to minimize the risk of exploitation. Avoid using the `f path` argument in the affected HTTP POST Request Handler until the issue is resolved. It is recommended to retire and replace the affected products, as they are no longer supported by the maintainer.