Network attached storage vendor D-Link has urged users of end-of-life products to retire and replace them, after news emerged of mass exploitation of legacy kit via a newly discovered vulnerability.
Now described as CVE-2024-3273, the high-severity vulnerability has been assigned a CVSS score of 7.3.
D-Link confirmed in an advisory that the following EOL models are exposed to exploitation of the vulnerability as they are no longer receiving firmware updates: DNS-340L, DNS-320L, DNS-327L and DNS-325.
Non-profit threat research organization the ShadowServer Foundation confirmed that threat actors are now actively targeting vulnerable NAS devices.
NAS devices are a popular target for botnet herders and ransomware actors as they are often managed by home users, which can mean they're less well-protected than enterprise systems.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Tue, 09 Apr 2024 14:40:04 +0000