CVE-2024-11068
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 11, 2024
Updated: Nov 15, 2024
CWE ID 648
Summary
CVE-2024-11068 is a vulnerability affecting the D-Link DSL6740C modem. It involves an Incorrect Use of Privileged APIs issue, which allows unauthenticated remote attackers to manipulate any user's password through the API. Successful exploitation of this vulnerability enables attackers to gain access to Web, SSH, and Telnet services using the compromised user account. This weakness could lead to unauthorized access and potential data breaches, underscoring the importance of applying the necessary patch or update to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.