HIGH🇬🇧 English

CVE-2024-1786

CVSS 7.5v3.1pub. 2024-02-23upd. 2024-12-17

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation of the argument username leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254576. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Dlink Dir 600m

    HW
    Dlink
    c1
  • Dlink Dir 600m Firmware

    OS
    Dlink
    3.08
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Memory
CWE
Referencje

Powiązane podatności

CVE-2019-13101CRITICAL9.8PL ✓ten sam produkt

Brak uwierzytelnienia dla strony wan.htm w D-Link DIR-600M

CVE-2019-7736CRITICAL9.8PL ✓ten sam produkt

D-Link DIR-600M: pominięcie uwierzytelnienia via bezpośrednie żądanie do wan.htm

CVE-2020-13960HIGH7.5ten sam produkt

D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolve...

CVE-2017-9100HIGH8.8ten sam produkt

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by en...

CVE-2017-5874HIGH8.8ten sam produkt

CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass aut...