Improper Access Control in D-Link DIR-816 A2 DDNS Service
CVE-2024-13102

6.9MEDIUM

Key Information:

Vendor

D-link

Vendor
CVE Published:
2 January 2025

Badges

👾 Exploit Exists

What is CVE-2024-13102?

A vulnerability impacting the D-Link DIR-816 A2's DDNS Service has been identified, leading to improper access controls. This security flaw allows remote attackers to manipulate the affected code located in the /goform/DDNS file, potentially resulting in unauthorized access. Given that the vulnerability has been publicly disclosed, stakeholders should prioritize assessing and mitigating the risk associated with this issue to prevent any potential exploitation.

Affected Version(s)

DIR-816 A2 1.10CNB05_R1B011D88210

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

yhryhryhr (VulDB User)
.
CVE-2024-13102 : Improper Access Control in D-Link DIR-816 A2 DDNS Service