Unrestricted File Upload Vulnerability in D-Link DAR-7000-40 V31R02B1413C
CVE-2024-4962

9.8CRITICAL

Key Information:

Vendor

D-link

Vendor
CVE Published:
16 May 2024

Badges

👾 Exploit Exists

What is CVE-2024-4962?

A vulnerability has been identified in the D-Link DAR-7000-40 where an unrestricted upload can be exploited through the manipulation of the /useratte/resmanage.php file. This flaw allows attackers to upload malicious files remotely. Importantly, this issue affects products that are no longer supported, underlining the need for users to replace end-of-life equipment to mitigate security threats. The vendor has confirmed the product's end-of-life status, making it critical for users to seek alternatives.

Affected Version(s)

DAR-7000-40 V31R02B1413C

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

H0e4a0r1t (VulDB User)
.