CVE-2024-41611

CRITICAL

D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04 - Use of Hard-coded Credentials in Telnet Service

Title source: llm
STIX 2.1

Description

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

Scores

CVSS v3 9.8
EPSS 0.0047
EPSS Percentile 64.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
dlink/dir-860l_firmware 1.10b04
Published Jul 30, 2024
Tracked Since Feb 18, 2026