MuddyWater APT – Active IOCs
October 2, 2024Multiple WordPress Plugins Vulnerabilities
October 2, 2024MuddyWater APT – Active IOCs
October 2, 2024Multiple WordPress Plugins Vulnerabilities
October 2, 2024Severity
Medium
Analysis Summary
CVE-2024-4960 CVSS:6.3
D-Link DAR-7000-40 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions by the interface/sysmanage/licenseauthorization.php script. By sending a specially-crafted HTTP request in the file_upload parameter, a remote attacker could exploit this vulnerability to upload a malicious PHP script, which could allow the attacker to execute arbitrary PHP code on the vulnerable system.
CVE-2024-4963 CVSS:6.3
D-Link DAR-7000-40 could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions by the /url/url.php script. By sending a specially crafted HTTP request in the file_upload parameter, a remote attacker could exploit this vulnerability to upload a malicious PHP script, which could allow the attacker to execute arbitrary PHP code on the vulnerable system.
Impact
- Gain Access
Indicators of Compromise
CVE
- CVE-2024-4960
- CVE-2024-4963
Affected Vendors
Affected Products
- D-Link DAR-7000-40 V31R02B1413C
Remediation
Refer to D-Link Website for patch, upgrade or suggested workaround information.