CVE-2024-3273Active Exploitation(dlink / dnr-202l)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for dlink dnr-202l systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument system leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259284. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-05-02. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dnr-202l
  • dnr-202l_firmware
  • dnr-322l
  • dnr-322l_firmware

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
dnr-202ldnr-202l_firmwarednr-322ldnr-322l_firmwarednr-326dnr-326_firmwaredns-1100-4dns-1100-4_firmwaredns-120dns-1200-05

8 versions affected across 40 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-28: 1Mentions · 2026-02-19: 2Mentions · 2026-05-06: 1Mentions · 2026-07-22: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-07-22: 1Exploit Tool / Code · 2026-07-22: 1Active Exploitation · 2026-02-19: 2Technical Details · 2026-01-28: 1Technical Details · 2026-05-06: 1Technical Details · 2026-07-22: 101-2802-1905-0607-22
Signal classification4 categories
Active Exploitation
240.0%
Disclosure
120.0%
PoC
120.0%
Exploit
120.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-02-192
Active Exploitation2
2026-05-061
PoC1
2026-07-221
Exploit1
Full discourse5 posts
  • clearbluejar@clearbluejar
    PoC

    pyghidra-mcp v0.2.0 is out with new --gui mode. 👀 Your local LLM drives a real Ghidra CodeBrowser, not a plugin. New blog post shows firmware RE of the CVE-2024-3273 RCE chain with Gemma4. https://clearbluejar.github.io/posts/pyghidra-mcp-meets-ghidra-gui-drive-project-wide-re-with-local-ai/

    Post summary

    The post announces a new PyGhidra‑MCP release and presents a firmware reverse engineering PoC for CVE‑2024‑3273’s RCE chain using Gemma4, without indicating active exploitation or patch information.

    019048453.4K
    2.2K followersView on X
  • RST Cloud@rst_cloud
    Exploit

    #threatreport #HighCompleteness Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries | 20-07-2026 Source: https://hunt.io/blog/open-directory-nginx-rift-ghost-cms-multi-cve Key details below ↓ 💀Threats: Adaptixc2_tool, Supershell, Nginx_rift_vuln, Clickfix_technique, Impacket_tool, Goby_tool, 🎯Victims: Government, Universities, Healthcare, Financial services, Academic, Private sector 🏭Industry: Government, Financial, Education, Healthcare 🌐Geo: Italy, Brazil, France, Vietnam, Singapore, Australia, Chinese, South korea, United states, Indonesia, United kingdom, Ireland, New zealand 🔓CVEs: CVE-2023-27350 \[[Vulners](https://vulners.com/cve/CVE-2023-27350)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - papercut papercut_mf (<20.1.7, <21.2.11, <22.0.9) - papercut papercut_ng (<20.1.7, <21.2.11, <22.0.9) CVE-2026-4480 \[[Vulners](https://vulners.com/cve/CVE-2026-4480)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - redhat openshift_container_platform (4.0) - samba (<4.2.1) - redhat enterprise_linux (7.0, 8.0, 9.0, 10.0) CVE-2026-26980 \[[Vulners](https://vulners.com/cve/CVE-2026-26980)] - CVSS V3.1: *9.4*, - Vulners: Exploitation: True Soft: - ghost (<6.19.1) CVE-2024-3273 \[[Vulners](https://vulners.com/cve/CVE-2024-3273)] - CVSS V3.1: *7.3*, - Vulners: Exploitation: True Soft: - dlink dns-320l_firmware (1.01.0702.2013, 1.03.0904.2013, 1.11) CVE-2026-20253 \[[Vulners](https://vulners.com/cve/CVE-2026-20253)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - splunk (<10.0.7, <10.2.4) CVE-2026-42945 \[[Vulners](https://vulners.com/cve/CVE-2026-42945)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - f5 dos (le4.7.0, 4.8.0) - f5 nginx_gateway_fabric (le1.6.2, le2.5.1) - f5 nginx_ingress_controller (le3.7.2, le4.0.1, le5.4.1) - f5 nginx_instance_manager (le2.21.1) ... CVE-2017-10271 \[[Vulners](https://vulners.com/cve/CVE-2017-10271)] - CVSS V3.1: *7.5*, - Vulners: Exploitation: True Soft: - oracle weblogic_server (10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0, 12.2.1.2.0) 📚TTPs: ⚔️Tactics: 2 🛠️Technics: 0 🤖LLM extracted TTPs:` T1190, T1583.001, T1583.003, T1588.002, T1588.005, T1595.002 🧨IOCs: - IP: 2 - File: 4 - Hash: 1 - Domain: 4 💽Software: NGINX, PaperCut, WebLogic, mysql, GoDaddy 🔢Algorithms: sha256 🔠Functions: system ⚙️Win Services: print-spooler 📜Programming Languages: golang, javascript, python #threatreport: In mid-2026, significant vulnerabilities were discovered in NGINX and Ghost CMS, leading to potential cyber exploits targeting governmental and financial institutions across eleven countries. The two primary vulnerabilities included NGINX Rift (CVE-2026-42945), a heap overflow in the NGINX rewrite module, and a blind SQL injection in the Ghost CMS Content API (CVE-2026-26980). Public exploit code for both was released shortly after their discovery, prompting attackers to develop and deploy creative methods to leverage these vulnerabilities. An exposed directory on an active Singapore-based VPS revealed the operational details of a cyber threat actor leveraging these vulnerabilities. The directory, housing a variety of exploits, contained tools for multiple attack techniques, including reverse shell setup and out-of-band (OOB) DNS callbacks to confirm malware execution. The target sectors indicated a strategic approach, primarily focusing on high-value entities like federal governments, educational institutions, healthcare providers, and financial services. The NGINX Rift vulnerability was used in targeted attempts to exploit live infrastructure. An exploitation script (http://poc.py) relied on specific memory addresses and settings that necessitated a low-security environment, indicating a phase of development rather than direct application on active targets. The actor’s exploration revealed little success during these attempts. On the other hand, the Ghost CMS exploit allowed the attacker to interact with the database without authentication, making it easier to extract sensitive information. By running a public exploit script, the actor conducted checks to identify vulnerable hosts and subsequently attempted data extraction. The implications of CVE-2026-26980 extend beyond this singular event, as it had been previously associated with larger campaigns aimed at mass exploitation. Additional exploits in the toolkit included those targeting well-known vulnerabilities in systems such as PaperCut, Oracle WebLogic, and D-Link NAS devices. The operator's use of OOB verification methods, like directing DNS queries to uniquely generated subdomains, offered a means to validate successful exploit execution despite potential network response filtering. Command and control infrastructure included the presence of widely recognized exploitation frameworks like AdaptixC2 and Supershell, although these tools were not directly linked to any specific intrusion captured in the analysis. The operational artifacts uncovered indicated a systematic approach to database exploitation, along with diligent targeting across nations including Brazil, France, South Korea, and others, primarily within sectors that handle sensitive data. While specific compromise outcomes were not confirmed in the gathered evidence, this activity exemplified a competent cyber threat actor exploiting newly discovered vulnerabilities and old, effective techniques with awareness and precision. The existence of these exploits and their deliberate targeting underscores the need for heightened vigilance and proactive defense measures within the cybersecurity landscape to mitigate similar attacks.

    Post summary

    The report details the release of public exploit code for two high‑CVSS CVEs (NGINX Rift and Ghost CMS SQLi), describes the tools and scripts used, but does not confirm successful exploitation in the wild.

    00010302
    721 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2024-3273 — UAB Host Baltic Visit -- https://cti.loginsoft.com/ip/141.98.11.55 #Loginsoft #Cytellite #Cybersecurity #CVE20243273 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/Wanlx2EeGq

    Post summary

    The tweet announces that Cytellite detected activity targeting CVE-2024-3273 and links to a CTI page, indicating this vulnerability is being actively exploited.

    0000064
    19 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2024-3273 — UAB Host Baltic Visit -- https://cti.loginsoft.com/ip/141.98.11.55 #Loginsoft #Cytellite #Cybersecurity #CVE20243273 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/rBblTl93eZ

    Post summary

    The tweet reports recent detection of activity targeting CVE-2024-3273, implying the vulnerability is being actively exploited.

    0000058
    19 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 hono/jsx, Cross-Site Scripting, #CVE-2024-3273 (Critical) https://dailycve.com/hono-jsx-cross-site-scripting-cve-2024-3273-critical/

    Post summary

    The post references a critical cross‑site scripting vulnerability (CVE‑2024‑3273) in hono/jsx and links to a DailyCVE article for further details.

    0000068
    162 followersView on X
CPE platform detail43 entries

43 of 43 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdnr-202l---
OSdlinkdnr-202l_firmware---
HWdlinkdnr-322l---
OSdlinkdnr-322l_firmware---
HWdlinkdnr-326---
OSdlinkdnr-326_firmware---
HWdlinkdns-1100-4---
OSdlinkdns-1100-4_firmware---
HWdlinkdns-120---
HWdlinkdns-1200-05---
OSdlinkdns-1200-05_firmware---
OSdlinkdns-120_firmware---
HWdlinkdns-1550-04---
OSdlinkdns-1550-04_firmware---
HWdlinkdns-315l---
OSdlinkdns-315l_firmware---
HWdlinkdns-320---
OSdlinkdns-320_firmware---
HWdlinkdns-320l---
OSdlinkdns-320l_firmware1.01.0702.2013--
OSdlinkdns-320l_firmware1.03.0904.2013--
OSdlinkdns-320l_firmware1.11--
HWdlinkdns-320lw---
OSdlinkdns-320lw_firmware---
HWdlinkdns-321---
OSdlinkdns-321_firmware---
HWdlinkdns-323---
OSdlinkdns-323_firmware---
HWdlinkdns-325---
OSdlinkdns-325_firmware1.01--
HWdlinkdns-326---
OSdlinkdns-326_firmware---
HWdlinkdns-327l---
OSdlinkdns-327l_firmware1.00.0409.2013--
OSdlinkdns-327l_firmware1.09--
HWdlinkdns-340l---
OSdlinkdns-340l_firmware1.08--
HWdlinkdns-343---
OSdlinkdns-343_firmware---
HWdlinkdns-345---
OSdlinkdns-345_firmware---
HWdlinkdns-726-4---
OSdlinkdns-726-4_firmware---

Explore more