SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  D-Link NAS Devices Command Injection Using Hardcoded Credentials

Category: IoT-ATTACKS      

This vulnerability affects multiple D-Link NAS devices, including models DNS-340L, DNS-320L, DNS-327L, and DNS-325, among others. The vulnerability lies within the nas_sharing.cgi uri, which is vulnerable due to two main issues: a backdoor facilitated by hardcoded credentials, and a command injection vulnerability via the system parameter.


Relevant Information