CVE-2024-4960: D-Link DAR-7000-40 licenseauthorization.php unrestricted upload

Published May 16, 2024
·
Updated

UNSUPPORTED WHEN ASSIGNED A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C. Affected is an unknown function of the file interface/sysmanage/licenseauthorization.php. The manipulation of the argument fileupload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264528. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Affected Software

3 affected components
D-Link DAR-7000-40
All of the following
Dlink Dar-7000 Firmware=v31r02b1413c
Dlink Dar-7000

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove D-Link DAR-7000-40 V31R02B1413C from your environment.

    Retire the unsupported D-Link DAR-7000-40 device and replace it with a supported product, as recommended by the vendor (end-of-life).

  2. Configuration

    Prevent exploitation of the vulnerability that allows unrestricted upload via the file_upload argument to sysmanage/licenseauthorization.php; disable/block the upload functionality or deny requests that include the file_upload parameter.

    D-Link DAR-7000-40 sysmanage/licenseauthorization.php file_upload = blocked
  3. Compensating control

    Because D-Link DAR-7000-40 V31R02B1413C is end-of-life and should be retired, isolate the device from untrusted networks (e.g., restrict remote access so the vulnerable sysmanage/licenseauthorization.php function cannot be reached).

  4. Compensating control

    If any interface for sysmanage/licenseauthorization.php is exposed externally, restrict access (e.g., firewall/ACL) so remote attackers cannot reach the endpoint.

Event History

May 16, 2024
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-4960?

CVE-2024-4960 has been classified as critical due to the potential for unrestricted file uploads.

2

How do I fix CVE-2024-4960?

To mitigate CVE-2024-4960, it is recommended to update the D-Link DAR-7000-40 firmware to the latest version.

3

What is affected by CVE-2024-4960?

CVE-2024-4960 affects the D-Link DAR-7000-40 router, specifically the file interface/sysmanage/licenseauthorization.php.

4

What type of vulnerability is CVE-2024-4960?

CVE-2024-4960 is an unauthorized file upload vulnerability.

5

Can CVE-2024-4960 lead to further attacks?

Yes, CVE-2024-4960 can allow attackers to execute arbitrary code on the affected system, leading to potential data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203