CVE-2024-1786

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 23, 2024
Updated: Dec 17, 2024
CWE ID 120

Summary

CVE-2024-1786 is a critical vulnerability affecting the Telnet Service component in out-of-support D-Link DIR-600M C1 3.08 routers. An attacker can exploit this issue by manipulating the username argument, leading to a buffer overflow. This vulnerability can be exploited remotely, and the exploit has already been publicly disclosed. This issue is only relevant to unsupported routers, as the vendor, D-Link, has confirmed that the product is end-of-life and should be retired and replaced.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share