Got an old D-Link NAS device? Dump it like a D-Link!

DNS-340L, DNS-320L, DNS-327L and DNS-325 all need to be deleted

There are four models of D-Link NAS, all of which have reached end-of-service and should absolutely be disconnected immediately if you connect them to anything. All four have a backdoor with a severity rating of 9.8 and no fixes. D-Link is standing by their recommendation to replace these devices with newer models, as they have no plans to reverse their decision to no longer support EoS devices.

The flaw is unlikely to be something you can fix yourself, it’s a hard-coded username without a password, and that username is well known around the web. Users of these four models have enough permissions to trigger remote code execution, which will cause all kinds of nightmares for those storing data on the device.

It’s up to you whether to replace them with other D-Link devices or if you want to shop around!

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *