« Volver al listado

CVE-2024-45696

Estado: AnalizadaAlta (8.8)—

Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45696",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45696",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-16T13:30:40.299168Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "D-Link",
          "product": "DIR-X4860 A1",
          "versions": [
            {
              "status": "affected",
              "version": "1.00"
            },
            {
              "status": "affected",
              "version": "1.04"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "D-Link",
          "product": "COVR-X1870",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "1.02"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:dlink:covr-x1870_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "covr-x1870_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "1.02"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:dlink:dir-x4860_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dir-x4860_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00"
            },
            {
              "status": "affected",
              "version": "1.04"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-16T07:15:03.037",
  "references": [
    {
      "url": "https://www.twcert.org.tw/en/cp-139-8087-c3e70-2.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-8086-93ed5-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-912"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service and log in using hard-coded credentials. The telnet service enabled through this method can only be accessed from within the same local network as the device."
    },
    {
      "lang": "es",
      "value": "Algunos modelos de enrutadores inalámbricos D-Link contienen funciones ocultas. Al enviar paquetes específicos al servicio web, el atacante puede habilitar por la fuerza el servicio Telnet e iniciar sesión con credenciales codificadas. Solo se puede acceder al servicio Telnet habilitado mediante este método desde la misma red local que el dispositivo."
    }
  ],
  "lastModified": "2026-06-17T07:54:40.673",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:covr-x1870_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6608842-4B33-49CA-BB9A-7484370CB8DC",
              "versionEndExcluding": "1.03b01"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:covr-x1870:*:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C8F856BE-5848-486A-87F4-A2FFC42BABF1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dir-x4860_firmware:1.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E8E188F-287F-4F63-BA73-7B7D666607BB"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dir-x4860_firmware:1.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9969A74F-33DE-4CC2-8F9E-962FD8EEE3BA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dir-x4860:a1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8497D176-6D8B-41BC-B377-0963EF6C24B2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}