

Multiple Juniper Networks Products Vulnerabilities
July 23, 2024
Cybercriminals Launch Cryptomining Attacks Using Misconfigured Jenkins Script Console – Active IOCs
July 23, 2024
Multiple Juniper Networks Products Vulnerabilities
July 23, 2024
Cybercriminals Launch Cryptomining Attacks Using Misconfigured Jenkins Script Console – Active IOCs
July 23, 2024Severity
High
Analysis Summary
CVE-2024-40505 CVSS:8.4
D-Link DAP-1650 could allow a local attacker to gain elevated privileges on the system, caused by a flaw in hedwig.cgi component. By sending a specially crafted request, an attacker could exploit this vulnerability to escalate privilleges.
CVE-2024-39202 CVSS:8.8
D-Link DIR-823X could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability using the dhcpd_startip parameter at /goform/set_lan_settings to execute arbitrary commands on the system.
Impact
- Gain Access
- Privilege Escalation
Indicators of Compromise
CVE
- CVE-2024-40505
- CVE-2024-39202
Affected Vendors
Affected Products
- D-Link DAP-1650 1.03
- D-Link DIR-823X 240126
Remediation
Refer to D-Link Website for patch, upgrade, or suggested workaround information.