CVE-2024-11067

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 15, 2024
CWE ID 23

Summary

CVE-2024-11067 is a newly identified vulnerability affecting the D-Link DSL6740C modem. This issue permits unauthenticated remote attackers to exploit a Path Traversal flaw, granting them the ability to read sensitive system files. Furthermore, since the device uses the MAC address as its default password, an attacker who successfully exploits this vulnerability can obtain the MAC address and attempt to log in to the modem, potentially gaining unauthorized access. This vulnerability poses a significant risk to the security of networks utilizing the DSL6740C modem and requires immediate attention from administrators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share