D-Link Routers Vulnerable to Path Traversal Attacks
CVE-2024-6044

6.5MEDIUM

Key Information:

Vendor
D-link
Status
G403
G415
G416
M18
Vendor
CVE Published:
17 June 2024

Summary

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL.

Affected Version(s)

E15 earlier < 1.20.01

E30 earlier < 1.10.02

G403 earlier < 1.10.01

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.