PT-2024-7559 · D Link · D-Link Dsl-6740C

Chiao-Lin Yu

+1

·

Published

2024-10-30

·

Updated

2024-11-01

·

CVE-2024-48271

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DSL-6740C version 6.TR069.20211230
Description The issue is related to the use of weak password requirements in the D-Link DSL-6740C router's software component. This could allow a remote attacker to escalate their privileges. The vulnerability is due to the use of insecure default credentials for Administrator access, which could be exploited by attackers to bypass authentication and gain elevated access to the device through a brute-force attack.
Recommendations For D-Link DSL-6740C version 6.TR069.20211230, update the firmware as soon as possible and change the default credentials to secure ones. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2024-08960
CVE-2024-48271

Affected Products

D-Link Dsl-6740C