Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6525


** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-270368. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.


Published

2024-07-05T13:15:11.170

Last Modified

2024-11-21T09:49:48.273

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 2.7 (LOW)

CVSSv2 Vector

AV:N/AC:L/Au:M/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: MULTIPLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

6.4

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-502

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System dlink dar-7000_firmware ≤ 2023-09-22 Yes
Hardware dlink dar-7000 - No

References