Vulnerabilities

Critical RCE bug in 92,000 D-Link NAS devices exploited in attacks

0

Attackers are now actively targeting over 92,000 end-of-life D-Link Network Attached Storage (NAS) devices exposed online and unpatched against a critical remote code execution (RCE) zero-day flaw.

The security vulnerability (CVE-2024-3273) is the result of a backdoor facilitated through a hardcoded account (username “messagebus” with an empty password) and a command injection issue via the “system” parameter.

Threat actors are now exploiting these two security flaws to deploy a variant of the Mirai malware (skid.x86). Mirai variants are usually designed to add infected devices to a botnet that can be used in large-scale distributed denial-of-service (DDoS) attacks.

Now, these attacks were observed by cybersecurity firm GreyNoise and threat monitoring platform ShadowServer. Two weeks earlier, security researcher Netsecfish disclosed the vulnerability after D-Link informed them that these end-of-life devices would not be patched.

The described vulnerability affects multiple D-Link NAS devices, including models DNS-340L, DNS-320L, DNS-327L, and DNS-325, among others.

On successful exploitation of this vulnerability, an attacker could execute arbitrary commands on the system, potentially leading to unauthorized access to sensitive information, modification of system configurations, or denial of service conditions.

According to a D-Link spokesperson, they no longer support these end-of-life (EOL) NAS devices. D-Link recommends retiring these products and replacing them with products that receive firmware updates.

The spokesperson added that these NAS devices do not have automatic online updating or alert delivery capabilities, making it impossible to notify the owners of these ongoing attacks.

After the disclosure, D-Link released a security advisory to notify owners about the security vulnerability and advise them to retire or replace the affected devices as soon as possible.

It also created a support page for legacy devices, warning owners to apply the latest security and firmware updates available through the legacy support website, although that wouldn’t protect their devices from attackers.

The company also warned that if US consumers continue to use these devices against D-Link’s recommendation, they must make sure the device has the last known firmware.

However, NAS devices shouldn’t be exposed online since they are commonly targeted in ransomware attacks to steal or encrypt data.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Beware of the new Latrodectus Malware

Previous article

Android spyware campaign targets users in India and Pakistan

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *