Critical Flaw in D-Link NAS Devices Exposes Thousands to Remote Command Attacks

Red | Vulnerability Report
Download PDF

A critical security vulnerability, CVE-2024-10914, is putting thousands of D-Link NAS devices at serious risk worldwide. This flaw, found in the `account_mgr.cgi` script, allows attackers to remotely execute arbitrary commands by sending tailored HTTP GET requests. With over 61,000 systems potentially exposed, this vulnerability presents a substantial risk of unauthorized access and control over affected devices.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox