CVE-2024-11066
published 2024-11-11CVE-2024-11066: The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary…
PriorityP352high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.80%
76.0th percentile
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dsl6740c | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
blogs_bleepingcomputer·2024-11-19
D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
## D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
## Bill Toulas
D-Link is warning customers to replace end-of-life VPN router models after a critical unauthenticated, remote code execution vulnerability was discovered that will not be fixed on these devices.
The flaw was discovered and reported to D-Link by security researcher 'delsploit,' but technical details have been withheld from the public to avoid triggering mass exploitation attempts in the wild.
The vulnerability, which does not have a CVE assigned to it yet, impacts all hardware and firmware revisions of DSR-150 and DSR-150N, and also DSR-250 and DSR-250N from firmware 3.13 to 3.17B901C.
These VPN routers, popular in home office and small business settings, were sold internationally and reached their
Bleepingcomputer
D-Link won’t fix critical bug in 60,000 exposed EoL modems
blogs_bleepingcomputer·2024-11-12·CVSS 7.2
CVE-2024-11068 [HIGH] D-Link won’t fix critical bug in 60,000 exposed EoL modems
## D-Link won’t fix critical bug in 60,000 exposed EoL modems
## Bill Toulas
In an advisory today, D-Link announced that it won't fix the issue and recommends "retiring and replacing D-Link devices that have reached EOL/EOS."
Chaio-Lin Yu reported to TWCERTCC two other vulnerabilities, an OS command injection and a path traversal issue:
The three flaws issues are summarized as follows:
CVE-2024-11068 : Flaw that allows unauthenticated attackers to modify any user’s password through privileged API access, granting them access to the modem’s Web, SSH, and Telnet services. (CVSS v3 score: 9.8 “critical”).
CVE-2024-11067 : Path traversal vulnerability allowing unauthenticated attackers to read arbitrary system files, retrieve the device’s MAC address, and attempt login using the default
2024-11-11
Published