First published: Tue Aug 06 2024(Updated: )
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
D-Link DIR-300 Firmware | =1.06b05_ww | |
D-Link DIR-300 | =a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41616 has a high severity due to the presence of hardcoded credentials in the Telnet service, which can lead to unauthorized access.
To fix CVE-2024-41616, update the D-Link DIR-300 firmware to a version that does not include hardcoded credentials.
CVE-2024-41616 affects D-Link DIR-300 devices running firmware version 1.06B05_WW.
Hardcoded credentials are usernames and passwords that are embedded in the device firmware, making them publicly accessible without authorization.
CVE-2024-41616 is a concern for network security because attackers can exploit hardcoded Telnet credentials to gain unrestricted access to the affected device.