CVE-2024-11067
published 2024-11-11CVE-2024-11067: The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.30%
67.2th percentile
The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the MAC address, attackers can obtain the MAC address through this vulnerability and attempt to log in to the device using the default password.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dsl6740c | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
blogs_bleepingcomputer·2024-11-19
D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
## D-Link urges users to retire VPN routers impacted by unfixed RCE flaw
## Bill Toulas
D-Link is warning customers to replace end-of-life VPN router models after a critical unauthenticated, remote code execution vulnerability was discovered that will not be fixed on these devices.
The flaw was discovered and reported to D-Link by security researcher 'delsploit,' but technical details have been withheld from the public to avoid triggering mass exploitation attempts in the wild.
The vulnerability, which does not have a CVE assigned to it yet, impacts all hardware and firmware revisions of DSR-150 and DSR-150N, and also DSR-250 and DSR-250N from firmware 3.13 to 3.17B901C.
These VPN routers, popular in home office and small business settings, were sold internationally and reached their
Bleepingcomputer
D-Link won’t fix critical bug in 60,000 exposed EoL modems
blogs_bleepingcomputer·2024-11-12·CVSS 7.2
CVE-2024-11068 [HIGH] D-Link won’t fix critical bug in 60,000 exposed EoL modems
## D-Link won’t fix critical bug in 60,000 exposed EoL modems
## Bill Toulas
In an advisory today, D-Link announced that it won't fix the issue and recommends "retiring and replacing D-Link devices that have reached EOL/EOS."
Chaio-Lin Yu reported to TWCERTCC two other vulnerabilities, an OS command injection and a path traversal issue:
The three flaws issues are summarized as follows:
CVE-2024-11068 : Flaw that allows unauthenticated attackers to modify any user’s password through privileged API access, granting them access to the modem’s Web, SSH, and Telnet services. (CVSS v3 score: 9.8 “critical”).
CVE-2024-11067 : Path traversal vulnerability allowing unauthenticated attackers to read arbitrary system files, retrieve the device’s MAC address, and attempt login using the default
2024-11-11
Published