
CVE-2024-10914 is a critical vulnerability affecting the D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L up to version 20241028. The function cgi_user_add in the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add is the culprit, allowing attackers to inject operating system commands remotely.
CVE-2024-10914 est une vulnérabilité critique affectant les D-Link DNS-320, DNS-320LW, DNS-325 et DNS-340L jusqu'à la version 20241028. La fonction cgi_user_add dans le fichier /cgi-bin/account_mgr.cgi?cmd=cgi_user_add est responsable, permettant aux attaquants d'injecter des commandes du système d'exploitation à distance.
Utilisation du script:
'./cve-2024-10914-exploit.sh -u <target_url> -c '