CVE-2024-9004: D-Link DAR-7000 Backup_Server_commit.php os command injection
A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/BackupServercommit.php. The manipulation of the argument host leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9004?
CVE-2024-9004 is classified as a critical vulnerability.
How do I fix CVE-2024-9004?
To fix CVE-2024-9004, update the D-Link DAR-7000 firmware to a version greater than 2024-09-12.
What type of vulnerability is CVE-2024-9004?
CVE-2024-9004 is an OS command injection vulnerability.
Which devices are affected by CVE-2024-9004?
CVE-2024-9004 affects the D-Link DAR-7000 firmware versions up to and including 2024-09-12.
Can CVE-2024-9004 be exploited remotely?
Yes, CVE-2024-9004 can be exploited remotely through manipulation of the 'host' argument.