7.5
CVE-2024-11067
- EPSS 0.39%
- Published 11.11.2024 08:15:08
- Last modified 24.11.2024 15:15:06
- Source twcert@cert.org.tw
- Teams watchlist Login
- Open Login
The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the MAC address, attackers can obtain the MAC address through this vulnerability and attempt to log in to the device using the default password.
Data is provided by the National Vulnerability Database (NVD)
Dlink ≫ Dsl6740c Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.39% | 0.594 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
twcert@cert.org.tw | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-23 Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.