D-Link修補Wi-Fi路由器高風險漏洞
支付動態 · 2024-09-18

D-Link公布旗下3款路由器的5項漏洞,這些漏洞涉及記憶體緩衝區溢位、隱藏功能,以及作業系統命令注入

本週D-Link發布資安公告,指出旗下的DIR-X5460、DIR-X4860、COVR-X1870等無線路由器設備存在5項漏洞:CVE-2024-45694、CVE-2024-45695、CVE-2024-45696、CVE-2024-45697、CVE-2024-45698,CVSS風險評分介於8.8至9.8,他們發布新版韌體予以修補。

值得留意的是,上述的弱點都是經由台灣電腦網路危機處理暨協調中心(TWCERT/CC)通報,D-Link強調他們在接獲通報的90天內完成修補,但未透露這段期間是否已出現漏洞遭到利用的情況。

根據CVSS風險評分,這些漏洞當中較為嚴重的是被評為重大層級的CVE-2024-45694、CVE-2024-45695、CVE-2024-45697,其中,CVE-2024-45694、CVE-2024-45695與路由器的網頁服務有關,為記憶體緩衝區溢位漏洞,攻擊者可在未經身分驗證的情況下,遠端在設備上執行任意程式碼;另一個漏洞CVE-2024-45697則與產品隱藏的功能有關,在建立WAN連接埠連線時,路由器會逕自啟用Telnet服務,攻擊者有機會利用寫死的帳號資料存取,並執行作業系統層級命令。

熱門文章
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
B2B Tech Infrastructure Gains Momentum in Philippine Gaming Sector
Southeast Asia
Indiana online casino bill stalls in House committee
Regulation
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
Vietnam’s Controlled Gaming Shift Gains Ground, But Domestic Demand Still Lags
Southeast Asia
JILI Partners with Cricket Legend AB de Villiers (ABD) to Launch Exclusive Branded Game Series 100% 11
Sports Game
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
Kazakhstan plans to penalise online casino promotions
Regulation
Online gambling, crypto pose ongoing money laundering risks in Philippines, analyst says
Southeast Asia
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
首頁
遊戲
合作
發現
我的