Get the latest tech news

D-Link Won't Fix Critical Flaw Affecting 60,000 Older NAS Devices


D-Link confirmed no fix will be issued for the over 60,000 D-Link NAS devices that are vulnerable to a critical command injection flaw (CVE-2024-10914), allowing unauthenticated attackers to execute arbitrary commands through unsanitized HTTP requests. The networking company advises users to retire ...

The networking company advises users to retire or isolate the affected devices from public internet access. [...] A search that Netsecfish conducted on the FOFA platform returned 61,147 results at 41,097 unique IP addresses for D-Link devices vulnerable to CVE-2024-10914. In a security bulletin today, D-Link has confirmed that a fix for CVE-2024-10914 is not coming and the vendor recommends that users retire vulnerable products.

Get the Android app

Or read this on Slashdot

Read more on:

Photo of Link

Link

Photo of NAS

NAS

Photo of critical flaw

critical flaw

Related news:

News photo

Apple Will Let You Share AirTag Locations With a Link

News photo

Toy maker Mattel is apologizing after sending out a run of Wicked branded toys with a link to a porn website on the box.

News photo

D-Link won’t fix critical flaw affecting 60,000 older NAS devices