Record summary

CVE-2024-57045 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2025 · Source: CVE List

Nuclei templates

1
ProjectDiscoveryCRITICALD-Link DIR-859 - Information DisclosureCVSS 9.8

A critical information disclosure vulnerability exists in D-Link devices where sensitive device account information including credentials can be retrieved by sending an unauthenticated request to `/getcfg.php` endpoint with the parameter `SERVICES=DEVICE.ACCOUNT`. This could allow attackers to obtain administrative credentials and gain full control of the affected device.

Impact

Unauthenticated attackers can retrieve administrative credentials and sensitive device account information, enabling full device compromise.

Remediation

Update D-Link DIR-859 router to the latest firmware version that addresses CVE-2024-57045 as specified in D-Link's security bulletin.

WeaknessesCWE-200
Authorsritikchaddha
Template tagscvecve2024dlinkdisclosureunauthvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: title:"D-Link"
FOFA: title="D-Link"

Source: ProjectDiscovery

References

3