D-Link停止維護的多款NAS機型被揭露多個漏洞,全球逾9.2萬臺設備恐被植入後門
· 2024-04-09

D-Link已不再維護的網路儲存設備被發現新漏洞,攻擊者有可能將其用於任意命令,或是竄改系統配置,甚至發動阻斷服務(DoS)攻擊

研究人員Netsecfish揭露存在於D-Link網路儲存設備(NAS)的漏洞CVE-2024-3273,影響DNS-340L、DNS-320L、DNS-327L、DNS-325等機種,CVSS風險評分為7.3,估計全球有92,589臺NAS曝險。這些設備還是因為直接連上網際網路而被找到,若將未連上網路的設備也納入,受影響範圍應該還會更大。

此漏洞存在於名為nas_sharing.cgi的URI,主要涵蓋2項弱點,其中一個是因為帳密寫死而形成的後門,另一個則是系統參數存在命令注入漏洞,上述弱點一旦遭到利用,攻擊者就有機會在NAS執行任意命令,從而存取敏感資訊、竄改系統配置,或是造成阻斷服務(DoS)。

值得留意的是,由於這些NAS設備的生命週期已經結束(EOL),D-Link表明將不會提供相關修補,並呼籲用戶應儘速淘汰這些設備。

Popular articles
British gambling levy rates confirmed for each vertical
Regulation
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
PropellerAds Shared a New iGaming Case Study: 97,674 Installs and 12,701 Deposits in 3 Months
Marketing
New Jersey July Gambling Revenue Hits $606M, Sweeps Casinos Banned
Regulation
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Indiana online casino bill stalls in House committee
Regulation
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
Gaming & Technology Expo Makes a Powerful Entrance in CDMX
Marketing
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
Kazakhstan plans to penalise online casino promotions
Regulation
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
Home
Game
Cooperation
Find
My