D-Link Routers Incorrect Use Of Privileged APIs (CVE-2024-11068)

critical Nessus Plugin ID 211678

Synopsis

The remote router is affected by an incorrect use of privileged APIs vulnerability.

Description

The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.

Note that Nessus has not tested for this issue but has instead relied only on the router's self-reported model.

Solution

Upgrade to a supported device.

See Also

https://www.twcert.org.tw/en/cp-139-8234-0514c-2.html

Plugin Details

Severity: Critical

ID: 211678

File Name: d-link_router_cve-2024-11068.nasl

Version: 1.1

Type: remote

Family: CGI abuses

Published: 11/21/2024

Updated: 11/21/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-11068

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:dlink:dsl6740c_firmware

Required KB Items: www/d-link, d-link/model

Patch Publication Date: 11/11/2024

Vulnerability Publication Date: 11/11/2024

Reference Information

CVE: CVE-2024-11068