CVE-2024-57045: Critical severity d-link dir-859 a1 vulnerability
A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57045?
CVE-2024-57045 is classified as a high severity vulnerability due to the potential for unauthorized access to user credentials.
How do I fix CVE-2024-57045?
To fix CVE-2024-57045, update the D-Link DIR-859 router firmware to a version later than A3 1.05.
What type of attack does CVE-2024-57045 enable?
CVE-2024-57045 enables an attacker to bypass authentication and obtain user credentials through a forged POST request.
Which devices are affected by CVE-2024-57045?
All D-Link DIR-859 routers operating on firmware version A3 1.05 and earlier are affected by CVE-2024-57045.
What information can attackers obtain through CVE-2024-57045?
Attackers exploiting CVE-2024-57045 can obtain valid usernames and passwords from the affected router's configuration.