Unrestricted File Upload Vulnerability in D-Link DAR-7000-40 Router
CVE-2024-4961
6.3MEDIUM
What is CVE-2024-4961?
A severe security vulnerability exists in the D-Link DAR-7000-40 router, specifically within the 'onlineuser.php' file. This flaw allows attackers to perform unrestricted file uploads, posing a significant risk of remote exploitation. Attackers can manipulate the 'file_upload' argument without sufficient validation, enabling malicious files to be uploaded to the device. Notably, this vulnerability affects products that are no longer supported, as confirmed by the vendor. Users are strongly advised to retire the affected product and consider replacement options to mitigate potential security risks. For more information, consult the VDB-264529 entry or D-Link's announcement.
Affected Version(s)
DAR-7000-40 V31R02B1413C