Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-10914 — Proof-of-concept exploit for CVE-2024-10914, demonstrating OS command injection in D-Link NAS devices (DNS-320, DNS-320LW, DNS-325, DNS-340L) via the cgi_user_add function, enabling remote code execution. | Kitploit
Tools/GitHubGitHub/dragonxzh/cve-2024-10914
Vulnerability AnalysisExploitationWeb Application ExploitationCommand and ControlRemote Access Tool
GitHubdragonxzh/cve-2024-10914

CVE-2024-10914

Proof-of-concept exploit for CVE-2024-10914, demonstrating OS command injection in D-Link NAS devices (DNS-320, DNS-320LW, DNS-325, DNS-340L) via the cgi_user_add function, enabling remote code execution.

View Repository
81 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-10914

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

Affected Devices

DNS-320 Version 1.00

DNS-320LW Version 1.01.0914.2012

DNS-325 Version 1.01, Version 1.02

DNS-340L Version 1.08

Download Tool