D-Link一款終止支援的無線路由器有重大漏洞,恐被用於RCE攻擊
支付動態 · 2024-09-04

已於4年前停止支援的D-Link無線路由器DIR-846W出現重大層級漏洞,研究人員通報此事並得到D-Link證實,但該公司表明不會處理

8月27日資安研究人員yali-10012透露,D-Link旗下路由器設備DIR-846W存在4個嚴重的RCE漏洞,而且其中3個可在未經身分驗證的情況下利用,9月1日D-Link發布資安公告證實確有此事,但因為這款設備已於2020年終止支援(EOS),他們不會進行修補,呼籲用戶應停止使用。

這些漏洞是:CVE-2024-41622、CVE-2024-44340、CVE-2024-44341,以及CVE-2024-44342,CVSS風險評分介於8.8至9.8,其中,僅有風險較低的CVE-2024-44340,攻擊者必須先通過身分驗證才能利用,其餘能夠在未經身分驗證就能觸發的漏洞,美國國家漏洞資料庫(NVD)皆將其風險評為9.8分。

值得留意的是,已停止支援的D-Link設備漏洞,今年出現數起攻擊行動,4月有研究人員發現NAS設備漏洞CVE-2024-3273,隨後就有嘗試利用的跡象;5月傳出無線路由器DIR-645遭到大規模攻擊,過程中駭客利用已知漏洞CVE-2015-2051。

Popular articles
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
Full House at GAT Expo Cartagena 2026 Academic Agenda
Online Game
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
Indiana online casino bill stalls in House committee
Regulation
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
HUIDU Invites You to Booth T70 at iGB L!VE 2026 — Let’s Ignite London This July!
HUIDU Focus
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
New Jersey July Gambling Revenue Hits $606M, Sweeps Casinos Banned
Regulation
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
Home
Game
Cooperation
Find
My