What it is
CVE-2024-10914 is an unauthenticated vulnerability affecting D-Link DNS-320 and 3 other products. A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as...
Vulnerability report
DNS-320 Command Injection
D-Link / DNS-320 · 1.00
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2024-10914 is an unauthenticated vulnerability affecting D-Link DNS-320 and 3 other products. A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as...
Is it exploited?
Yes. Previdian sensors observed exploitation attempts with confirmed confidence. Also confirmed by third-party sources.
Who is affected?
D-Link / DNS-320 1.00.
What should we do?
Patch immediately, validate internet-facing exposure, and monitor for matching requests.
Overview
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
In D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L bis 20241028 wurde eine kritische Schwachstelle ausgemacht. Hierbei betrifft es die Funktion cgi_user_add der Datei /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. Durch Manipulation des Arguments name mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Die Komplexität eines Angriffs ist eher hoch. Sie gilt als schwierig ausnutzbar. Der Exploit steht zur öffentlichen Verfügung.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
The Shadowserver
A trusted third party reported exploitation.
Previdian sensor
Previdian first observed exploitation attempts targeting this vulnerability in our honeypot sensors.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| The Shadowserver First | 2025-04-24 00:00 UTC |
| Previdian Sensors | 2026-09-19 00:10 UTC |
| The Hacker News | 2026-10-05 15:33 UTC |
Operational indicators for this CVE are listed under Detection.
Sensor telemetry
Previdian sensors recorded exploitation attempts targeting this vulnerability. The cards and chart show volume, unique attackers, and daily activity.
213
Attempts observed
22
Unique attacker IPs
11
Attacker countries
BG · CH · DE · ER · FR · HK · JP · NL · TM · US · YE
54
Sensors observed
CVE-2024-10914 exploitation attempts over the last 91 days
Daily events observed by Previdian sensors
Updated 10 Oct 2026
First observed 12 Jun 2026 · Last observed 02 Oct 2026
Pro adds sensor region and window summaries. Enterprise adds raw IPs, paths, User-Agents, and payloads.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
Nuclei template detected 25 Apr 2025.
View Nuclei template (opens in new tab)No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Attacker IP indicators observed · available in Pro and Enterprise.
Sensor-derived attacker IP indicators are available to Pro and Enterprise accounts under Detection and through the Pro API.
Learn about Pro API accessScanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-10914.yaml | 25 Apr 2025 |
Risk and context
CVSS v4.0
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
96.3%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · The Hacker News
Ravie LakshmananOct 05, 2026Vulnerability / Malware Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because...
Read full advisoryCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:H/Au:N/C:C/I:C/A:C
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
15:33 UTC
Exploitation attested by an external source
00:09 UTC
Indicators of compromise recorded
00:09 UTC
Evidence-backed exploitation signal
14:20 UTC
Public proof-of-concept code published
00:00 UTC
Scanner coverage available
00:00 UTC
High-confidence, third-party attested exploitation
13:31 UTC
Vulnerability disclosed publicly
07:07 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2024-10914
Free JSON includes basic KEV fields{
"cve_id": "CVE-2024-10914",
"confidence": "Confirmed",
"cvss_score": 9.2,
"cvss_estimated": false,
"epss_score": 0.96284,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": true
},
"sensor_telemetry": { "attempts": 213, "sensors": 54 }
}