Improper Access Control in D-Link DIR-816 A2 DDNS Service
CVE-2024-13102
Key Information:
- Vendor
- D-link
- Status
- Vendor
- CVE Published:
- 2 January 2025
Badges
Summary
A vulnerability impacting the D-Link DIR-816 A2's DDNS Service has been identified, leading to improper access controls. This security flaw allows remote attackers to manipulate the affected code located in the /goform/DDNS file, potentially resulting in unauthorized access. Given that the vulnerability has been publicly disclosed, stakeholders should prioritize assessing and mitigating the risk associated with this issue to prevent any potential exploitation.
Affected Version(s)
DIR-816 A2 1.10CNB05_R1B011D88210
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved