Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitrary settings within the device's XML database, including the administrator’s password.
2025-08-25T14:15:30.463
2025-09-02T18:17:07.257
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | dlink | dsl-7740c_firmware | 6.tr069.20211230 | Yes |
Hardware | dlink | dsl-7740c | - | No |