📦 Dns 327l Firmware

by Dlink

🔍 What is Dns 327l Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-3272

CRITICAL CVSS 9.8 Apr 4, 2024

This vulnerability in D-Link network storage devices allows remote attackers to access hard-coded credentials via HTTP GET requests to the nas_sharing.cgi endpoint. Attackers can gain unauthorized acc...

CVE-2024-7832

HIGH CVSS 8.8 Aug 15, 2024

This critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the 'user' parameter in the photocenter_mgr.cgi CGI script. It affec...

CVE-2024-7830

HIGH CVSS 8.8 Aug 15, 2024

A critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the photo_name parameter in the cgi_move_photo function. This affects m...

CVE-2024-7828

HIGH CVSS 8.8 Aug 15, 2024

A critical buffer overflow vulnerability in D-Link NAS devices allows remote attackers to execute arbitrary code by manipulating the album_name parameter in the photocenter_mgr.cgi script. This affect...

CVE-2024-8213

MEDIUM CVSS 6.3 Aug 27, 2024

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious input into the f_source_dev parameter of the hd_config.cgi scrip...

CVE-2024-8211

MEDIUM CVSS 6.3 Aug 27, 2024

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious input into the f_newly_dev parameter of the hd_config.cgi script...

CVE-2024-8133

MEDIUM CVSS 6.3 Aug 24, 2024

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices via command injection in the HTTP POST handler. It affects multiple end-of-life D-Link ...

CVE-2024-8131

MEDIUM CVSS 6.3 Aug 24, 2024

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by exploiting a command injection flaw in the web interface's module management functio...

CVE-2024-8129

MEDIUM CVSS 6.3 Aug 24, 2024

This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious commands through the f_job_name parameter in HTTP POST requests....