CVE-2024-11046
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 10, 2024
Updated: Nov 13, 2024
CWE ID 78
CWE ID 77
Summary
CVE-2024-11046 is a critical vulnerability affecting the D-Link DI-8003 with firmware version 16.07.16A1. This issue lies in the upgrade_filter_asp function within the /upgrade_filter.asp file. An attacker can exploit this by manipulating the path argument, resulting in OS command injection. The vulnerability is remote and has been publicly disclosed, increasing the risk of exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.