CVE-2024-45696
16.09.2024, 07:15
Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device.Enginsight
Vendor | Product | Version |
---|---|---|
dlink | covr-x1870_firmware | 𝑥 < 1.03b01 |
dlink | dir-x4860_firmware | 1.00 |
dlink | dir-x4860_firmware | 1.04 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration