D-Link DSL6740C Modem Vulnerable to OS Command Injection
CVE-2024-11062

7.2HIGH

Key Information:

Vendor
D-link
Status
Vendor
CVE Published:
11 November 2024

Summary

The D-Link DSL6740C modem is vulnerable to an OS Command Injection flaw that permits remote attackers with administrative privileges to exploit specific functionalities associated with SSH and Telnet. This security issue allows for the injection and execution of arbitrary system commands, potentially compromising the modem's integrity and the security of the entire network. This vulnerability emphasizes the importance of securing devices against such remote exploits, reinforcing the need for timely updates and security measures.

Affected Version(s)

DSL6740C 0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.