CVE-2024-13103

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 284
CWE ID 266

Summary

CVE-2024-13103 is a newly disclosed critical vulnerability affecting D-Link DIR-816 A2 1.10CNB05_R1B011D88210 routers. The flaw, located in the Virtual Service Handler component, involves improper access controls during the processing of the /goform/form2AddVrtsrv.cgi file. This issue can be exploited remotely, allowing unauthorized access to the affected system. The exact number of potentially impacted devices and the specific attack vectors are currently unknown, but the existence and details of the exploit have been made public. Users are strongly advised to apply patches or updates as soon as they become available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share