CVE-2024-11068

Published Nov 11, 2024

Last updated 2 days ago

Overview

Description
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.
Source
twcert@cert.org.tw
NVD status
Analyzed
CNA Tags
unsupported-when-assigned

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

twcert@cert.org.tw
CWE-648

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. به تازگی برای هزاران روتر D-Link مدل DSL-6740C آسیب پذیری با کد شناسایی CVE-2024-11068 که از نوع password change می باشد ، منتشر شده است. این مدل از روتر های Dlink از امسال توسط Dlink پشتیبانی نمی شوند و در واقع تجهیزات و روتر های EOL محسوب می شوند. https://t.co/Poz3aKY03t https:

    @AmirHossein_sec

    15 Nov 2024

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-11068 (Published: 2024-11-11) affects D-Link products. Vulnerable versions may expose users to security risks. Ensure you update to the latest firmware to mitigate potential exploits. Stay secure! More info: https://t.co/w7aakRICsw #CyberSecurity #DLink

    @transilienceai

    15 Nov 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2024-11068 (Published: 2024-11-11) - A critical vulnerability in D-Link TVN-202411013 affects multiple versions. Users are urged to update to the latest firmware immediately to mitigate risks. Stay secure! More info: https://t.co/w7aakRICsw #CyberSecurity #DLink

    @transilienceai

    15 Nov 2024

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Gravi vulnerabilità nei NAS e modem D-Link per assenza di patch su dispositivi EOL Sicurezza Informatica, attacchi informatici, CVE-2024-10914, CVE-2024-11068, cybersecurity, D-Link, dispositivi, DSL6740C, EOL, modem, NAS, vulnerabilità https://t.co/5XJ5iRrdr1 https://t.co/c9UZ72

    @matricedigitale

    14 Nov 2024

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️⚠️ CVE-2024-11068 (CVSS 9.8): Critical D-Link DSL-6740C Flaw, Immediate Replacement Advised 🎯59k+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/exBkbbei3A FOFA Query:app="D_Link-DSL-6740C" 🔖Refer: https://t.co/SH1khMFuLI #OSINT… h

    @fofabot

    12 Nov 2024

    743 Impressions

    0 Retweets

    11 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CVE Alert: Critical D-Link Incorrect Use of Privileged APIs vulnerability🚨 Vulnerability Details: CVE-2024-11068 (CVSS 9.8/10) D-Link Incorrect Use of Privileged APIs vulnerability Impact A Successful exploit may allows unauthenticated attackers to remotely modify any… http

    @CyberxtronTech

    12 Nov 2024

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨🚨D-Link DSL-6740C Modem Exposed to Multiple Security Vulnerabilities CVE-2024-11068 (CVSS 9.8): Incorrect Use of Privileged APIs CVE-2024-11067 (CVSS 7.5): Arbitrary File Reading through Path Traversal CVE-2024-11062, 11063, 11064, 11065 , 11066(CVSS 7.2): OS Command Injection

    @zoomeye_team

    12 Nov 2024

    386 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. [CVE-2024-11068: CRITICAL] D-Link DSL6740C modem vulnerable to remote attacks, allowing unauthorized password modifications through Privileged APIs, risking access to Web, SSH, and Telnet services.#cybersecurity,#vulnerability https://t.co/ESwtNIeOXd https://t.co/g2uQhX7SAR

    @CveFindCom

    11 Nov 2024

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations