This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Evidence dossier
CVE-2024-3273
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
gen-56ccdaf9Normalized restatement
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
- State
- PUBLISHED
- Published
- Apr 4, 2024
- Updated
- Oct 21, 2025
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 100.0%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
D-Link Multiple NAS Devices Command Injection Vulnerability
Probability 0.999970000000; percentile 0.999880000000
Applicability
Cited product scope
[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknown[{"status": "affected", "version": "20240403"}]unknowncpe:2.3:h:dlink:dnr-202l:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dnr-322l:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dnr-326:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-1100-4:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-120:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-1200-05:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-1550-04:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-315l:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-320:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-320l:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-320lw:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-321:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-323:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-325:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-326:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-327l:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-340l:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-343:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-345:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:dlink:dns-726-4:-:*:*:*:*:*:*:*constrainedcpe:2.3:o:dlink:dnr-202l_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dnr-322l_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dnr-326_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-1100-4_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-1200-05_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-120_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-1550-04_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-315l_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-320_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-320l_firmware:1.01.0702.2013:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-320l_firmware:1.03.0904.2013:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-320l_firmware:1.11:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-320lw_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-321_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-323_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-325_firmware:1.01:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-326_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-327l_firmware:1.00.0409.2013:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-327l_firmware:1.09:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-340l_firmware:1.08:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-343_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-345_firmware:-:*:*:*:*:*:*:*supportedcpe:2.3:o:dlink:dns-726-4_firmware:-:*:*:*:*:*:*:*supportedAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LAV:N/AC:L/Au:N/C:P/I:P/A:PLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.