CVE-2024-6044

CWE-22Path Traversal3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.6%
top 29.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 17

Description

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages15 packages

CVEListV5d-link/e15earlier1.20.01
CVEListV5d-link/e30earlier1.10.02
CVEListV5d-link/m18earlier1.10.01
CVEListV5d-link/m30earlier1.10.02
CVEListV5d-link/m32earlier1.10.02

🔴Vulnerability Details

2
GHSA
GHSA-rr4p-qrv5-g999: Certain models of D-Link wireless routers have a path traversal vulnerability2024-06-17
CVEList
D-Link router - Arbitrary File Reading2024-06-17