CVE-2024-29385: Command Injection
Published Mar 22, 2024
·Updated
DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgimain function.
Affected Software
3 affected components
DIR DIR-845L<=1.01KRb03
All of the following
Dlink Dir-845l Firmware<=1.01krb03
Dlink Dir-845l
Event History
Mar 22, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-29385?
CVE-2024-29385 is considered a critical vulnerability due to its potential for unauthenticated remote code execution.
2
How do I fix CVE-2024-29385?
To fix CVE-2024-29385, upgrade the DIR-845L router firmware to a version higher than v1.01KRb03.
3
What type of vulnerability is CVE-2024-29385?
CVE-2024-29385 is an unauthenticated remote code execution vulnerability.
4
What is affected by CVE-2024-29385?
CVE-2024-29385 affects DIR-845L routers running firmware version 1.01KRb03 or earlier.
5
Can CVE-2024-29385 be exploited remotely?
Yes, CVE-2024-29385 can be exploited remotely without authentication.