CVE-2024-6045
Severity CVSS v4.0:
Pending analysis
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
17/06/2024
Last modified:
15/04/2026
Description
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398
- https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html
- https://www.twcert.org.tw/tw/cp-132-7879-da630-1.html
- https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398
- https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html
- https://www.twcert.org.tw/tw/cp-132-7879-da630-1.html



