Vulnerability Description
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398
- https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html
- https://www.twcert.org.tw/tw/cp-132-7879-da630-1.html
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398
- https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html
- https://www.twcert.org.tw/tw/cp-132-7879-da630-1.html
FAQ
What is CVE-2024-6045?
CVE-2024-6045 is a vulnerability with a CVSS score of 8.8 (HIGH). Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessin...
How severe is CVE-2024-6045?
CVE-2024-6045 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6045?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.