CVE-2024-57045
D-Link DIR-859 - Information Disclosure
Record summary
CVE-2024-57045 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2025 · Source: CVE List
Nuclei templates
1ProjectDiscoveryCRITICALD-Link DIR-859 - Information DisclosureCVSS 9.8
A critical information disclosure vulnerability exists in D-Link devices where sensitive device account information including credentials can be retrieved by sending an unauthenticated request to `/getcfg.php` endpoint with the parameter `SERVICES=DEVICE.ACCOUNT`. This could allow attackers to obtain administrative credentials and gain full control of the affected device.
Impact
Unauthenticated attackers can retrieve administrative credentials and sensitive device account information, enabling full device compromise.
Remediation
Update D-Link DIR-859 router to the latest firmware version that addresses CVE-2024-57045 as specified in D-Link's security bulletin.
Source: ProjectDiscovery