CVE-2024-45698
published 2024-09-16CVE-2024-45698: Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use…
PriorityP267critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.14%
63.0th percentile
Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| d-link | dir-x4860_a1 | — | — |
| d-link | dir-x4860_a1 | — | — |
| dlink | dir-x4860_firmware | — | — |
| dlink | dir-x4860_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-45698 exploits improper input validation in the telnet service of affected D-Link routers; detect unauthenticated telnet login attempts using hard-coded credentials followed by OS command injection on affected models (COVR-X1870, DIR-X4860, DIR-X5460) ↗
- →Monitor for telnet service activity (TCP port 23) on D-Link COVR-X1870, DIR-X4860, and DIR-X5460 devices, especially authentication attempts from external/WAN-side sources ↗
- →D-Link routers are commonly targeted by malware botnets; correlate telnet-based exploitation attempts against these models with known botnet C2 infrastructure ↗
- ·Vulnerable firmware versions are below v1.03B01 (COVR-X1870), v1.04B05 (DIR-X4860), and v1.11B04 (DIR-X5460); patched devices running these versions or later are not affected ↗
- ·CVE-2024-45698 (CVSS 8.8) is distinct from CVE-2024-45697 (CVSS 9.8); the latter enables telnet automatically when the WAN port is plugged in, while CVE-2024-45698 concerns input validation abuse once telnet is accessible — both share the hard-coded credentials attack vector ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2024-09-16
Published