Description
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Published: 2024-08-19
Score: 5.3 Medium
EPSS: 11.9% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-48762 A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
History

Tue, 20 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell dnr-202l
Dell dnr-202l Firmware
Dell dnr-322l
Dell dnr-322l Firmware
Dell dnr-326
Dell dnr-326 Firmware
Dell dns-1100-4
Dell dns-1100-4 Firmware
Dell dns-120
Dell dns-1200-05
Dell dns-1200-05 Firmware
Dell dns-120 Firmware
Dell dns-1550-04
Dell dns-1550-04 Firmware
Dell dns-315l
Dell dns-315l Firmware
Dell dns-320
Dell dns-320 Firmware
Dell dns-320l
Dell dns-320l Firmware
Dell dns-320lw
Dell dns-320lw Firmware
Dell dns-321
Dell dns-321 Firmware
Dell dns-323
Dell dns-323 Firmware
Dell dns-325
Dell dns-325 Firmware
Dell dns-326
Dell dns-326 Firmware
Dell dns-327l
Dell dns-327l Firmware
Dell dns-340l
Dell dns-340l Firmware
Dell dns-343
Dell dns-343 Firmware
Dell dns-345
Dell dns-345 Firmware
Dell dns-726-4
Dell dns-726-4 Firmware
CPEs cpe:2.3:h:dell:dnr-202l:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dnr-322l:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dnr-326:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-1100-4:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-1200-05:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-120:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-1550-04:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-315l:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-320:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-320l:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-320lw:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-321:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-323:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-325:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-326:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-327l:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-340l:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-343:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-345:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:dns-726-4:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dnr-202l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dnr-322l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dnr-326_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-1100-4_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-1200-05_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-120_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-1550-04_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-315l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-320_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-320l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-320lw_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-321_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-323_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-325_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-326_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-327l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-340l_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-343_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-345_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:dns-726-4_firmware:-:*:*:*:*:*:*:*
Vendors & Products Dell
Dell dnr-202l
Dell dnr-202l Firmware
Dell dnr-322l
Dell dnr-322l Firmware
Dell dnr-326
Dell dnr-326 Firmware
Dell dns-1100-4
Dell dns-1100-4 Firmware
Dell dns-120
Dell dns-1200-05
Dell dns-1200-05 Firmware
Dell dns-120 Firmware
Dell dns-1550-04
Dell dns-1550-04 Firmware
Dell dns-315l
Dell dns-315l Firmware
Dell dns-320
Dell dns-320 Firmware
Dell dns-320l
Dell dns-320l Firmware
Dell dns-320lw
Dell dns-320lw Firmware
Dell dns-321
Dell dns-321 Firmware
Dell dns-323
Dell dns-323 Firmware
Dell dns-325
Dell dns-325 Firmware
Dell dns-326
Dell dns-326 Firmware
Dell dns-327l
Dell dns-327l Firmware
Dell dns-340l
Dell dns-340l Firmware
Dell dns-343
Dell dns-343 Firmware
Dell dns-345
Dell dns-345 Firmware
Dell dns-726-4
Dell dns-726-4 Firmware

Mon, 19 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dnr-202l Firmware
Dlink dnr-322l Firmware
Dlink dnr-326 Firmware
Dlink dns-1100-4 Firmware
Dlink dns-1200-05 Firmware
Dlink dns-120 Firmware
Dlink dns-1550-04 Firmware
Dlink dns-315l Firmware
Dlink dns-320 Firmware
Dlink dns-320l Firmware
Dlink dns-320lw Firmware
Dlink dns-321 Firmware
Dlink dns-323 Firmware
Dlink dns-325 Firmware
Dlink dns-326 Firmware
Dlink dns-327l Firmware
Dlink dns-340l Firmware
Dlink dns-343 Firmware
Dlink dns-345 Firmware
Dlink dns-726-4 Firmware
CPEs cpe:2.3:o:dlink:dnr-202l_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dnr-322l_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dnr-326_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-1100-4_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-1200-05_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-120_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-1550-04_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-315l_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-320_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-320l_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-320lw_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-321_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-323_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-325_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-326_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-327l_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-340l_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-343_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-345_firmware:20240814:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dns-726-4_firmware:20240814:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dnr-202l Firmware
Dlink dnr-322l Firmware
Dlink dnr-326 Firmware
Dlink dns-1100-4 Firmware
Dlink dns-1200-05 Firmware
Dlink dns-120 Firmware
Dlink dns-1550-04 Firmware
Dlink dns-315l Firmware
Dlink dns-320 Firmware
Dlink dns-320l Firmware
Dlink dns-320lw Firmware
Dlink dns-321 Firmware
Dlink dns-323 Firmware
Dlink dns-325 Firmware
Dlink dns-326 Firmware
Dlink dns-327l Firmware
Dlink dns-340l Firmware
Dlink dns-343 Firmware
Dlink dns-345 Firmware
Dlink dns-726-4 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Title D-Link DNS-1550-04 myMusic.cgi cgi_write_playlist command injection
Weaknesses CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Dell Dnr-202l Dnr-202l Firmware Dnr-322l Dnr-322l Firmware Dnr-326 Dnr-326 Firmware Dns-1100-4 Dns-1100-4 Firmware Dns-120 Dns-1200-05 Dns-1200-05 Firmware Dns-120 Firmware Dns-1550-04 Dns-1550-04 Firmware Dns-315l Dns-315l Firmware Dns-320 Dns-320 Firmware Dns-320l Dns-320l Firmware Dns-320lw Dns-320lw Firmware Dns-321 Dns-321 Firmware Dns-323 Dns-323 Firmware Dns-325 Dns-325 Firmware Dns-326 Dns-326 Firmware Dns-327l Dns-327l Firmware Dns-340l Dns-340l Firmware Dns-343 Dns-343 Firmware Dns-345 Dns-345 Firmware Dns-726-4 Dns-726-4 Firmware
Dlink Dnr-202l Firmware Dnr-322l Firmware Dnr-326 Firmware Dns-1100-4 Firmware Dns-1200-05 Firmware Dns-120 Firmware Dns-1550-04 Firmware Dns-315l Firmware Dns-320 Firmware Dns-320l Firmware Dns-320lw Firmware Dns-321 Firmware Dns-323 Firmware Dns-325 Firmware Dns-326 Firmware Dns-327l Firmware Dns-340l Firmware Dns-343 Firmware Dns-345 Firmware Dns-726-4 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-08-19T18:23:40.353Z

Reserved: 2024-08-19T09:43:35.228Z

Link: CVE-2024-7922

cve-icon Vulnrichment

Updated: 2024-08-19T18:10:26.021Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-19T15:15:09.403

Modified: 2024-08-20T16:20:25.403

Link: CVE-2024-7922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses