CVE-2024-45696
HIGHDescription
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device.
Is your site exposed to CVE-2024-45696?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| dlink | covr-x1870_firmware |
| dlink | covr-x1870 |
| dlink | dir-x4860_firmware |
| dlink | dir-x4860_firmware |
| dlink | dir-x4860 |
References
Frequently Asked Questions
What is CVE-2024-45696? +
How severe is CVE-2024-45696? +
What products are affected by CVE-2024-45696? +
How do I check if I'm vulnerable to CVE-2024-45696? +
Related Vulnerabilities
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not …
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, …
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 …
Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located …
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized …
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets …