CVE-2024-4961

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Affected by this vulnerability is an unknown functionality of the file /user/onlineuser.php. The manipulation of the argument file_upload leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264529 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
Configurations

No configuration.

History

21 Nov 2024, 09:43

Type Values Removed Values Added
References () https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/%3CWHB%7Cj%5CIbSU0m4%3A_/D-LINK-DAR-7000_upload_%20onlineuser.php.pdf - () https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/%3CWHB%7Cj%5CIbSU0m4%3A_/D-LINK-DAR-7000_upload_%20onlineuser.php.pdf -
References () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354 - () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10354 -
References () https://vuldb.com/?ctiid.264529 - () https://vuldb.com/?ctiid.264529 -
References () https://vuldb.com/?id.264529 - () https://vuldb.com/?id.264529 -
References () https://vuldb.com/?submit.333779 - () https://vuldb.com/?submit.333779 -

01 Aug 2024, 21:15

Type Values Removed Values Added
Summary
  • (es) ** NO SOPORTADO CUANDO SE ASIGNÓ ** Se encontró una vulnerabilidad clasificada como crítica en D-Link DAR-7000-40 V31R02B1413C. Una función desconocida del archivo /user/onlineuser.php es afectada por esta vulnerabilidad. La manipulación del argumento file_upload conduce a una carga sin restricciones. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-264529. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el mantenedor. NOTA: Se contactó al proveedor rápidamente y se confirmó de inmediato que el producto ha llegado al final de su vida útil. Debería retirarse y reemplazarse.

16 May 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-16 06:15

Updated : 2024-11-21 09:43


NVD link : CVE-2024-4961

Mitre link : CVE-2024-4961

CVE.ORG link : CVE-2024-4961


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type