« Volver al listado

CVE-2024-7715

Estado: AplazadaMedia (5.3)—

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240812. It has been classified as critical. This affects the function sprintf of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument filter leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Leer descripción completaMostrar menos

NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (20)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-7715",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cna@vuldb.com"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-7715",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-13T14:40:07.670088Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@vuldb.com",
      "affectedData": [
        {
          "vendor": "D-Link",
          "product": "DNS-120",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNR-202L",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-315L",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-320",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-320L",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-320LW",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-321",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNR-322L",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-323",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-325",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-326",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-327L",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNR-326",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-340L",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-343",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-345",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-726-4",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-1100-4",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-1200-05",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        },
        {
          "vendor": "D-Link",
          "product": "DNS-1550-04",
          "versions": [
            {
              "status": "affected",
              "version": "20240812"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:dlink:dns-120_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dnr-202l_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-315l_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-320_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-320l_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-320lw_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-321_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dnr-322l_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-323_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-325_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-326_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-327l_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dnr-326_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-340l_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-343_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-345_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-726-4_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-1100-4_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-1200-05_firmware:*:*:*:*:*:*:*:*",
            "cpe:2.3:o:dlink:dns-1550-04_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dns-120_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20240812"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-13T07:15:13.677",
  "references": [
    {
      "url": "https://github.com/BuaaIOTTeam/Iot_Dlink_NAS/blob/main/DNS_cgi_photo_search.md",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?ctiid.274281",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?id.274281",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/?submit.389261",
      "source": "cna@vuldb.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@vuldb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240812. It has been classified as critical. This affects the function sprintf of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument filter leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced."
    },
    {
      "lang": "es",
      "value": "** NO COMPATIBLE CUANDO SE ASIGNÓ ** Se encontró una vulnerabilidad en D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323 , DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 y DNS-1550 -04 hasta 20240812. Ha sido clasificada como crítica. Esto afecta a la función sprintf del archivo /cgi-bin/photocenter_mgr.cgi. La manipulación del filtro de argumentos conduce a la inyección de comandos. Es posible iniciar el ataque de forma remota. El exploit ha sido divulgado al público y puede utilizarse. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el fabricante. NOTA: Se contactó primeramente con el proveedor y se confirmó que el producto ha llegado al final de su vida útil. Debería retirarse y reemplazarse."
    }
  ],
  "lastModified": "2026-06-17T08:20:46.723",
  "sourceIdentifier": "cna@vuldb.com"
}