PoC-CVE-2024-10914
by GYATT - Saturday November 16, 2024 at 08:59 PM
#1
Greetings & Salutations, Breachforums community.

Today I am bringing to the table a 'Critical Command Injection Vulnerability in D-Link NAS Devices'

Description:

CVE-2024-10914 is a critical command injection vulnerability affecting legacy D-Link Network Attached Storage (NAS) devices. This flaw, with a CVSS score of 9.2, allows unauthenticated attackers to execute arbitrary shell commands by exploiting improper input validation in the cgi_user_add command.  The vulnerability can be triggered remotely using a specially crafted HTTP GET request, making it highly exploitable.


Link to checker on Github, reply below to get access if you are an un-upgraded member.
Hidden Content
You must register or login to view this content.


This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Threatening forum members
Reply
#2
Nice thanks i hope we will see you more
Reply
#3
Checking this as wel
Reply
#4
Checking this as wel !!!
Reply
#5
nice one fam, hope this works

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
This should be good, I cant wait to view the code!

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
Reply
#7
Thanks for the poc
Reply
#8
Nice thanks i hope we will see you more
Reply
#9
I want to exploit the vulnerability script
Reply
#10
Checking it out. Also banned for threatening members hahaha wow broo
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 41 3,683 11 hours ago
Last Post: Xploitd
  {SECRET} DATABASE OF EXPLOITS lulagain 435 26,424 Yesterday, 06:11 AM
Last Post: DirtyEra
  New Zer0 Day Wordpress A3g00n 81 3,356 Yesterday, 03:06 AM
Last Post: DirtyEra
  Wordpress Elementor 3.11.6 Exploit - Full Takeover TheGoodlife 102 19,716 May 04, 2026, 06:45 AM
Last Post: eztocard
  new wordpress website takeover vuln (video + poc ) zinzeur 314 28,335 Apr 30, 2026, 03:54 PM
Last Post: baku

Forum Jump:


 Users browsing this forum: 1 Guest(s)