« Volver al listado

CVE-2024-45694

Estado: AnalizadaCrítica (9.8)—

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45694",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45694",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-16T13:46:17.341670Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "twcert@cert.org.tw",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "twcert@cert.org.tw",
      "affectedData": [
        {
          "vendor": "D-Link",
          "product": "DIR-X5460 A1",
          "versions": [
            {
              "status": "affected",
              "version": "1.01"
            },
            {
              "status": "affected",
              "version": "1.02"
            },
            {
              "status": "affected",
              "version": "1.04"
            },
            {
              "status": "affected",
              "version": "1.10"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "D-Link",
          "product": "DIR-X4860 A1",
          "versions": [
            {
              "status": "affected",
              "version": "1.00"
            },
            {
              "status": "affected",
              "version": "1.04"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:dlink:dir-x4860_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dir-x4860_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.00"
            },
            {
              "status": "affected",
              "version": "1.04"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:o:dlink:dir-x5460_firmware:*:*:*:*:*:*:*:*"
          ],
          "vendor": "dlink",
          "product": "dir-x5460_firmware",
          "versions": [
            {
              "status": "affected",
              "version": "1.01"
            },
            {
              "status": "affected",
              "version": "1.02"
            },
            {
              "status": "affected",
              "version": "1.04"
            },
            {
              "status": "affected",
              "version": "1.10"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-16T07:15:02.610",
  "references": [
    {
      "url": "https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    },
    {
      "url": "https://www.twcert.org.tw/tw/cp-132-8080-7f494-1.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "twcert@cert.org.tw"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "twcert@cert.org.tw",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability to execute arbitrary code on the device."
    },
    {
      "lang": "es",
      "value": "El servicio web de ciertos modelos de enrutadores inalámbricos D-Link contiene una vulnerabilidad de desbordamiento de búfer basada en pila, que permite a atacantes remotos no autenticados explotar esta vulnerabilidad para ejecutar código arbitrario en el dispositivo."
    }
  ],
  "lastModified": "2026-06-17T07:54:40.450",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dir-x5460_firmware:1.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "41DB57EF-B020-4B06-A725-C568F7F4C8FF"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dir-x5460_firmware:1.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D95B7A3-E5E1-4553-AF4C-777843D43BA6"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dir-x5460_firmware:1.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E96AFAF8-4617-4AC9-AE3D-871A789F4018"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dir-x5460_firmware:1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67D9078D-7B51-4FD3-BAE3-2B20822DF7E3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dir-x5460:a1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2A276652-CC92-4DBB-8EA8-DF8E6797C794"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dlink:dir-x4860_firmware:1.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E8E188F-287F-4F63-BA73-7B7D666607BB"
            },
            {
              "criteria": "cpe:2.3:o:dlink:dir-x4860_firmware:1.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9969A74F-33DE-4CC2-8F9E-962FD8EEE3BA"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dlink:dir-x4860:a1:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8497D176-6D8B-41BC-B377-0963EF6C24B2"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "twcert@cert.org.tw"
}