CVE-2024-10914 is a critical vulnerability affecting the D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L up to version 20241028. The function cgi_user_add in the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add is the culprit, allowing attackers to inject operating system commands remotely.# CVE-2024-10914-Exploit
CVE-2024-10914 is a critical vulnerability affecting the D-Link DNS-320, DNS-320LW, DNS-325, and DNS-340L up to version 20241028. The function cgi_user_add in the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add is the culprit, allowing attackers to inject operating system commands remotely.
**Script Usage:**
'./cve-2024-10914-exploit.sh -u <target_url> -c <command>'
[4.0K] /data/pocs/837946e3c97b8517158f7c50d47cc6b543f8e044
├── [ 898] cve-2024-10914-exploit.sh
└── [ 397] README.md
0 directories, 2 files