PT-2024-7819 · D Link · D-Link Dsl6740C

Chiao-Lin Yu

+1

·

Published

2024-11-11

·

Updated

2024-11-24

·

CVE-2024-11068

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DSL6740C (affected versions not specified)
Description The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account. The vulnerability is actively exploited in the wild. It is estimated that over 59,000 results are found for the affected device, indicating a potentially large number of devices at risk.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling remote access to the device and enabling firewalls to minimize the risk of exploitation. Additionally, using strong passwords can help reduce the risk. It is advised to replace the modem immediately if possible.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09319
CVE-2024-11068

Affected Products

D-Link Dsl6740C