CVE-2024-4699
CVE-2024-4699 is a critical deserialization vulnerability found in D-Link DAR-8000-10 routers up to version 20230922. This flaw allows remote attackers to execute arbitrary code by manipulating the 'sql' argument in the /importhtml.php file. Although the CVSS score is 6.3, indicating a medium severity, the SVRS is 30. This lower SVRS, despite the potential for remote code execution, is because D-Link no longer supports the affected product. While the exploit is remotely triggerable, the end-of-life status mitigates the immediate risk, emphasizing that the device should be replaced to avoid potential exploitation. The vulnerability resides in CWE-502, highlighting the dangers of insecure deserialization practices. The presence of the 'In The Wild' tag suggests that exploitation attempts might have been observed.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.