Rewterz
Multiple Juniper Networks Products Vulnerabilities
July 23, 2024
Rewterz
Cybercriminals Launch Cryptomining Attacks Using Misconfigured Jenkins Script Console – Active IOCs
July 23, 2024

Multiple D-Link Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-40505 CVSS:8.4

D-Link DAP-1650 could allow a local attacker to gain elevated privileges on the system, caused by a flaw in hedwig.cgi component. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privilleges.

CVE-2024-39202 CVSS:8.8

D-Link DIR-823X could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability using the dhcpd_startip parameter at /goform/set_lan_settings to execute arbitrary commands on the system.

Impact

  • Gain Access
  • Privilege Escalation

Indicators of Compromise

CVE

  • CVE-2024-40505
  • CVE-2024-39202

Affected Vendors

D-Link

Affected Products

  • D-Link DAP-1650 1.03
  • D-Link DIR-823X 240126

Remediation

Refer to D-Link Website for patch, upgrade, or suggested workaround information.

CVE-2024-40505

CVE-2024-39202