Thousands of D-Link NAS devices have serious backdoor security issues

A high-severity vulnerability was recently discovered in certain D-Link Network Attached Storage (NAS) instances that could be used to execute malicious code, steal sensitive data, and conduct Denial-of-Service (DoS) attacks .

Cybersecurity researcher Netsecfish, who discovered the flaw, found that multiple instances of D-Link’s NAS devices contain a random command injection flaw in the “system” parameter, and a hardcoded account that can be used to access the device . As a result, hackers can execute commands as they please: