← Vulnerability feed

Vulnerability record · CVE-2024-0717 · published 19 January 2024

CVE-2024-0717: Dlink dir-825acg1 firmware information exposure vulnerability

Dlink · Dir 825acg1 Firmware

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

5.3 CVSS 3.1 Medium EPSS 18% · top 2.9% CWE-200 · Information exposure
5.3CVSS 3.1 base score, v2 5.0
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
44Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

44 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/999zzzzz/D-Link ExploitThird Party Advisory
https://vuldb.com/?ctiid.251542 Third Party Advisory
https://vuldb.com/?id.251542 Third Party Advisory
https://github.com/999zzzzz/D-Link ExploitThird Party Advisory
https://vuldb.com/?ctiid.251542 Third Party Advisory
https://vuldb.com/?id.251542 Third Party Advisory

Track CVE-2024-0717 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.7CVE-2011-4723D-Link DIR-300 router stores passwords in cleartextThe D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials di…KEVEPSS 3.1%analysed10.0CVE-2013-10069Dlink dir-600 firmware os command injection vulnerabilityThe web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…EPSS 17%9.8CVE-2024-41616Dlink dir-300 firmware hard-coded credentials vulnerabilityD-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.EPSS 0.76%9.8CVE-2023-31814Dlink dir-300 firmware vulnerabilityD-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.EPSS 0.89%9.8CVE-2013-7471Dlink dir-300 firmware command injection vulnerabilityAn issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 r…EPSS 24%9.3CVE-2022-50596Dlink dir-1260 firmware os command injection vulnerabilityD-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management inter…EPSS 4.1%9.3CVE-2013-10048Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, res…EPSS 17%8.8CVE-2024-5291Dlink dir-2150 firmware os command injection vulnerabilityD-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers …EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2024-0717), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.