Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to log into telnet and inject arbitrary OS commands, which can then be executed on the device.
2024-09-16T07:15:03.450
2024-10-15T10:15:02.853
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dir-x4860_firmware | 1.00 | Yes |
Operating System | dlink | dir-x4860_firmware | 1.04 | Yes |
Hardware | dlink | dir-x4860 | a1 | No |