github.com
https://github.com/yj94/Yj_learning/blob/main/Week16/D-LINK-POC.md CVE-2024-33113
MEDIUMNuclei
D-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure
Record summary
CVE-2024-33113 has a selected CVSS score of 5.3 (medium); EIP currently links 2 repository PoCs and 1 Nuclei template.
Description
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dir-845lBrowse d-link / dir-845lDefault status: unknown | CVE List | - | affected |
Proofs of concept
2Repository PoCs
GitHubFaLLenSKiLL1/CVE-2024-33113Repository PoCby FaLLenSKiLL1Stars: 4Not analyzed2 files
GitHubtekua/CVE-2024-33113Repository PoCby tekuaStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMD-LINK DIR-845L bsc_sms_inbox.php file - Information Disclosure
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
Impact
Unauthenticated attackers can access sensitive account and configuration information from the D-LINK DIR-845L router.
Remediation
Update D-LINK DIR-845L firmware to a version later than 1.01KRb03 that patches the information disclosure vulnerability.
Authorspussycat0x
Template tagscvecve2024dlinkinfo-leakvuln
CPE: cpe:2.3:h:dlink:dir-845l:*:*:*:*:*:*:*:*
Shodan: DIR-845L
https://github.com/FaLLenSKiLL1/CVE-2024-33113 https://github.com/yj94/Yj_learning/blob/main/Week16/D-LINK-POC.md
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33113