PT-2024-1919 · D Link · D-Link Dir-600M C1
Dmknght
·
Published
2024-02-22
·
Updated
2024-12-17
·
CVE-2024-1786
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DIR-600M C1 version 3.08
Description
A critical issue has been found in the Telnet Service component of the affected device, caused by a buffer overflow when manipulating the
username argument. This can be exploited remotely, potentially allowing an attacker to execute arbitrary code. The issue affects products that are no longer supported by the maintainer and should be retired and replaced.Recommendations
For D-Link DIR-600M C1 version 3.08, it is recommended to retire and replace the device as it is no longer supported by the maintainer. As a temporary workaround, consider disabling the Telnet Service until a replacement can be implemented. Restrict access to the device to minimize the risk of exploitation. Avoid using the
username argument in the Telnet Service until the issue is resolved by replacing the device.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dir-600M C1