Netsecfish

#1385of 53,607
159.4Total CVSS
Vulnerabilities · 24
Medium
15
High
4
Critical
5
PT-2024-7744
7.6
2024-11-06
D Link · D-Link Dns-320 · CVE-2024-10914
**Name of the Vulnerable Software and Affected Versions** D-Link DNS-320 versions prior to 20241028 D-Link DNS-320LW versions prior to 20241028 D-Link DNS-325 versions prior to 20241028 D-Link DNS-340L versions prior to 20241028 **Description** A critical vulnerability exists in D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L devices. The issue is a command injection flaw located in the `cgi user add` function of the `/cgi-bin/account mgr.cgi?cmd=cgi user add` file. Manipulation of the `name` argument allows for the execution of arbitrary operating system commands. The attack can be launched remotely. Exploitation is considered difficult, but a public exploit is available. Approximately 61,000 devices worldwide are estimated to be affected, with exploitation attempts observed starting November 12th. The vulnerability is due to insufficient input validation of the `name` parameter, enabling attackers to inject shell commands. **Recommendations** D-Link DNS-320: As D-Link will not release a patch, replace the device with a supported model or restrict access from external networks. D-Link DNS-320LW: As D-Link will not release a patch, replace the device with a supported model or restrict access from external networks. D-Link DNS-325: As D-Link will not release a patch, replace the device with a supported model or restrict access from external networks. D-Link DNS-340L: As D-Link will not release a patch, replace the device with a supported model or restrict access from external networks.
PT-2024-5614
5.3
2024-08-01
Provision Isr · Sh-8100A-2L · CVE-2024-7339
**Name of the Vulnerable Software and Affected Versions** TVT DVR TD-2104TS-CL (affected versions not specified) DVR TD-2108TS-HP (affected versions not specified) Provision-ISR DVR SH-4050A5-5L(MM) (affected versions not specified) AVISION DVR AV108T (affected versions not specified) TD-2116TE-HP (affected versions not specified) SH-8100A-2L(MM) (affected versions not specified) **Description** The issue is related to a lack of protection for service data in hybrid HD video recorders, which can be exploited remotely to disclose protected information. The vulnerability affects the `/queryDevInfo` file and may lead to sensitive data exposure. The exploit has been disclosed to the public and can be used. **Recommendations** For TVT DVR TD-2104TS-CL, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For DVR TD-2108TS-HP, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For Provision-ISR DVR SH-4050A5-5L(MM), consider applying restrictive firewalling immediately to minimize the risk of exploitation. For AVISION DVR AV108T, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For TD-2116TE-HP, consider applying restrictive firewalling immediately to minimize the risk of exploitation. For SH-8100A-2L(MM), consider applying restrictive firewalling immediately to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.