CVE-2024-57684
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jan 16, 2025
CWE ID 276
Summary
CVE-2024-57684 is a newly identified access control vulnerability affecting the component formDMZ.cgi in D-Link 816A2 routers running firmware v1.10CNB05_R1B011D88210. This issue permits unauthenticated attackers to manipulate the DMZ service setting via a specially crafted POST request. Successful exploitation could potentially lead to unauthorized access to the device or network, posing a significant risk to security. Users are strongly advised to apply the forthcoming patch or upgrade to a secure version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- D-Link Corporation