Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device.
2024-09-16T07:15:03.037
2024-09-19T21:42:36.557
Analyzed
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | covr-x1870_firmware | < 1.03b01 | Yes |
Hardware | dlink | covr-x1870 | * | No |
Operating System | dlink | dir-x4860_firmware | 1.00 | Yes |
Operating System | dlink | dir-x4860_firmware | 1.04 | Yes |
Hardware | dlink | dir-x4860 | a1 | No |