CVE-2024-7922

MEDIUM
Published Aug 19, 2024 Modified Aug 20, 2024 CWE-77

Description

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.

Is your site exposed to CVE-2024-7922?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Weakness Type (CWE)

CWE-77 CWE-77

Affected Products

Vendor Product
dell dns-120_firmware
dell dns-120
dell dnr-202l_firmware
dell dnr-202l
dell dns-315l_firmware
dell dns-315l
dell dns-320_firmware
dell dns-320
dell dns-320l_firmware
dell dns-320l
dell dns-320lw_firmware
dell dns-320lw
dell dns-321_firmware
dell dns-321
dell dnr-322l_firmware
dell dnr-322l
dell dns-323_firmware
dell dns-323
dell dns-325_firmware
dell dns-325
dell dns-326_firmware
dell dns-326
dell dns-327l_firmware
dell dns-327l
dell dnr-326_firmware
dell dnr-326
dell dns-340l_firmware
dell dns-340l
dell dns-343_firmware
dell dns-343
dell dns-345_firmware
dell dns-345
dell dns-726-4_firmware
dell dns-726-4
dell dns-1100-4_firmware
dell dns-1100-4
dell dns-1200-05_firmware
dell dns-1200-05
dell dns-1550-04_firmware
dell dns-1550-04

References

Frequently Asked Questions

What is CVE-2024-7922? +
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced. It has a CVSS v3.1 base score of 6.3 (MEDIUM).
How severe is CVE-2024-7922? +
CVE-2024-7922 has a CVSS v3.1 score of 6.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-7922? +
CVE-2024-7922 affects products from dell, specifically: dnr-202l, dnr-202l_firmware, dnr-322l, dnr-322l_firmware, dnr-326, dnr-326_firmware, dns-1100-4, dns-1100-4_firmware, dns-120, dns-1200-05, dns-1200-05_firmware, dns-120_firmware, dns-1550-04, dns-1550-04_firmware, dns-315l, dns-315l_firmware, dns-320, dns-320_firmware, dns-320l, dns-320l_firmware, dns-320lw, dns-320lw_firmware, dns-321, dns-321_firmware, dns-323, dns-323_firmware, dns-325, dns-325_firmware, dns-326, dns-326_firmware, dns-327l, dns-327l_firmware, dns-340l, dns-340l_firmware, dns-343, dns-343_firmware, dns-345, dns-345_firmware, dns-726-4, dns-726-4_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-7922? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-7922 — free, no signup required.