CVE-2024-11066

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dsl6740c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl6740c:-:*:*:*:*:*:*:*

History

24 Nov 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : unknown
CWE CWE-78
References
  • () https://www.bleepingcomputer.com/news/security/d-link-wont-fix-critical-bug-in-60-000-exposed-eol-modems/ -

15 Nov 2024, 18:22

Type Values Removed Values Added
References () https://www.twcert.org.tw/tw/cp-132-8225-3d882-1.html - () https://www.twcert.org.tw/tw/cp-132-8225-3d882-1.html - Third Party Advisory
References () https://www.twcert.org.tw/en/cp-139-8232-5d94e-2.html - () https://www.twcert.org.tw/en/cp-139-8232-5d94e-2.html - Third Party Advisory
CPE cpe:2.3:o:dlink:dsl6740c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dsl6740c:-:*:*:*:*:*:*:*
First Time Dlink dsl6740c Firmware
Dlink dsl6740c
Dlink

11 Nov 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 08:15

Updated : 2024-11-24 15:15


NVD link : CVE-2024-11066

Mitre link : CVE-2024-11066


JSON object : View

Products Affected

dlink

  • dsl6740c_firmware
  • dsl6740c
CWE

No CWE.