CWE
200
EPSS
0.052%
Advisory Published
Updated

CVE-2024-0717: D-Link Good Line Router v2 HTTP GET Request devinfo information disclosure

First published: Fri Jan 19 2024(Updated: )

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

Credit: cna@vuldb.com

Affected SoftwareAffected VersionHow to fix
All of
D-Link DIR-825ACG1<=2024-01-12
D-Link DIR-825ACG1
All of
D-Link DIR-841 Firmware<=2024-01-12
dlink DIR-841 firmware
All of
D-Link DIR-1260 Firmware<=2024-01-12
D-Link DIR-1260 Firmware
All of
D-Link DIR-822 firmware<=2024-01-12
D-Link DIR-822
All of
D-Link DIR-X1530 Firmware<=2024-01-12
D-Link DIR-X1530
All of
D-Link DIR-825 Firmware<=2024-01-12
D-Link DIR-825
All of
D-Link DIR-615<=2024-01-12
D-Link DIR-615
All of
D-Link DIR-842 Firmware<=2024-01-12
Dlink DIR-842E Firmware
All of
D-Link DIR-853 firmware<=2024-01-12
D-Link DIR-853
All of
D-Link DIR-1210 Firmware<=2024-01-12
D-Link DIR-1210
All of
D-Link DIR-806A Firmware<=2024-01-12
D-Link DIR-806A Firmware
All of
D-Link DIR-815S Firmware<=2024-01-12
D-Link DIR-815
All of
D-Link DSL-245GR Firmware<=2024-01-12
D-Link DSL-245GR
All of
D-Link DSL-G2452GR Firmware<=2024-01-12
dlink DSL-G2452GR firmware
All of
D-Link DIR-878 Firmware<=2024-01-12
dlink DIR-878 firmware
All of
D-Link DIR-825ACF Firmware<=2024-01-12
D-Link DIR-825ACF
All of
D-Link DIR-615T Firmware<=2024-01-12
D-Link DIR-615T
All of
D-Link DIR-300 Firmware<=2024-01-12
D-Link DIR-300
All of
TP-Link WR842ND<=2024-01-12
dlink DIR-842S firmware
All of
D-Link DIR-815S Firmware<=2024-01-12
D-Link DIR-815S Firmware
All of
D-Link DSL-2640U firmware<=2024-01-12
dlink DSL-2640U firmware
All of
D-Link DIR-2150 Firmware<=2024-01-12
D-Link DIR-2150
All of
D-Link DWR-921 Firmware<=2024-01-12
D-Link DWR-921
All of
dlink DIR-615 firmware<=2024-01-12
D-Link DIR-615
All of
D-Link DIR-620 Firmware<=2024-01-12
dlink DIR-620 firmware
All of
D-Link DVG-5402G firmware<=2024-01-12
dlink DVG-5402G firmware
All of
D-Link DIR-882 Firmware<=2024-01-12
D-Link DIR-882 Firmware
All of
dlink DWM-312W firmware<=2024-01-12
dlink DWM-312W
All of
D-Link DIR-815 AC Firmware<=2024-01-12
Dlink DIR-815
All of
D-Link DSL-224<=2024-01-12
D-Link DSL-224
All of
D-Link DWM-321<=2024-01-12
D-Link DWM-321
All of
dlink DIR-X1860 firmware<=2024-01-12
dlink DIR-X1860
All of
Dlink DAP-1360U Firmware<=2024-01-12
D-Link DAP-1360
All of
D-Link DIR-820 Firmware<=2024-01-12
D-Link DIR-820 Firmware
All of
dlink DIR-843 firmware<=2024-01-12
dlink DIR-843 firmware
All of
D-Link DVG-5402G/GFRU Firmware<=2024-01-12
D-Link DVG-5402G/GFRU
All of
dlink DWR-953 firmware<=2024-01-12
D-Link DWR-953
All of
D-Link DVG-N5402G/IL firmware<=2024-01-12
D-Link DVG-N5402G/IL
All of
D-Link DIR-825 AC Firmware<=2024-01-12
D-Link DIR-825ACF
All of
D-Link DIR-620S Firmware<=2024-01-12
D-Link DIR-620S
All of
D-Link DVG-N5402G<=2024-01-12
D-Link DVG-N5402G
All of
D-Link DSL-2750U<=2024-01-12
Dlink Dsl-2750b Firmware
All of
D-Link DIR-615GF Firmware<=2024-01-12
D-Link DIR-615GF
All of
D-Link DIR-816L Firmware<=2024-01-12
D-Link DIR-816 Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2024-0717?

    CVE-2024-0717 is classified as a critical vulnerability.

  • How do I fix CVE-2024-0717?

    To fix CVE-2024-0717, you should update the affected D-Link devices to the latest firmware version released by the manufacturer.

  • Which D-Link products are affected by CVE-2024-0717?

    CVE-2024-0717 affects several D-Link products including the DAP-1360, DIR-300, DIR-615 families, DIR-820, and other models listed in the CVE.

  • What are the potential impacts of CVE-2024-0717?

    The potential impacts of CVE-2024-0717 include unauthorized access to network settings and sensitive information.

  • When was CVE-2024-0717 discovered?

    CVE-2024-0717 was discovered recently and is associated with vulnerabilities found in firmware versions up to 2024-01-12.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203