Unrestricted File Upload Vulnerability in D-Link DAR-7000-40 Router
CVE-2024-4961
What is CVE-2024-4961?
A severe security vulnerability exists in the D-Link DAR-7000-40 router, specifically within the 'onlineuser.php' file. This flaw allows attackers to perform unrestricted file uploads, posing a significant risk of remote exploitation. Attackers can manipulate the 'file_upload' argument without sufficient validation, enabling malicious files to be uploaded to the device. Notably, this vulnerability affects products that are no longer supported, as confirmed by the vendor. Users are strongly advised to retire the affected product and consider replacement options to mitigate potential security risks. For more information, consult the VDB-264529 entry or D-Link's announcement.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DAR-7000-40 V31R02B1413C
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved