PT-2024-6868 · D Link · D-Link Dir-X5460A1+2
Raymond
·
Published
2024-09-13
·
Updated
2024-09-26
·
CVE-2024-45694
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link wireless routers (affected versions not specified)
D-Link DIR-X4860
D-Link DIR-X5460A1
D-Link COVR-X1870
Description
The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device. This flaw lets unauthenticated remote attackers execute code on the device without authorization.
Recommendations
For D-Link DIR-X4860, consider disabling the web service until a patch is available.
For D-Link DIR-X5460A1, restrict access to the web service to minimize the risk of exploitation.
For D-Link COVR-X1870, avoid using the web service until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link Covr-X1870
D-Link Dir-X4860
D-Link Dir-X5460A1