← Global Threat Landscape

CVE-2024-3272

CWE-798

Critical

103.8

RPS

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The manipulation of the argument user with the input messagebus leads to hard-coded credentials. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259283. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Source: NVD

Signals

CVSS
9.8
Critical · v3.1
EPSS
98.03%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Apr 2024
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-798
Published
4 Apr 2024
Last modified 30 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-3272

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2024-3272 · RPS 103.8 · DevSecure Intelligence