Unrestricted File Upload Vulnerability in D-Link DAR-7000-40 Router
CVE-2024-4961
Key Information:
- Vendor
- D-link
- Status
- Vendor
- CVE Published:
- 16 May 2024
Badges
Summary
A severe security vulnerability exists in the D-Link DAR-7000-40 router, specifically within the 'onlineuser.php' file. This flaw allows attackers to perform unrestricted file uploads, posing a significant risk of remote exploitation. Attackers can manipulate the 'file_upload' argument without sufficient validation, enabling malicious files to be uploaded to the device. Notably, this vulnerability affects products that are no longer supported, as confirmed by the vendor. Users are strongly advised to retire the affected product and consider replacement options to mitigate potential security risks. For more information, consult the VDB-264529 entry or D-Link's announcement.
Affected Version(s)
DAR-7000-40 V31R02B1413C
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved