← Back to browse · API

CVE-2024-7828

Severity
HIGH
CVSS
8.7
EPSS
0.16225
Risk score
40.48
CISA KEV
No
PoC
No
Published
2024-08-15
Modified
2024-08-16
First seen
2026-08-07
Aliases
EUVD-2024-48680, GHSA-C2P2-P654-9C4P
Products
D-Link:DNR-202L 20240814, D-Link:DNR-322L 20240814, D-Link:DNR-326 20240814, D-Link:DNS-1100-4 20240814, D-Link:DNS-120 20240814, D-Link:DNS-1200-05 20240814, D-Link:DNS-1550-04 20240814, D-Link:DNS-315L 20240814, D-Link:DNS-320 20240814, D-Link:DNS-320L 20240814, D-Link:DNS-320LW 20240814, D-Link:DNS-321 20240814, D-Link:DNS-323 20240814, D-Link:DNS-325 20240814, D-Link:DNS-326 20240814, D-Link:DNS-327L 20240814, D-Link:DNS-340L 20240814, D-Link:DNS-343 20240814, D-Link:DNS-345 20240814, D-Link:DNS-726-4 20240814
Sources
euvd EUVD-2024-48680

Description

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability affects the function cgi_set_cover of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument album_name leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

References