← Vulnerability feed

Vulnerability record · CVE-2024-41611 · published 30 July 2024

CVE-2024-41611: Dlink dir-860l firmware hard-coded credentials vulnerability

Dlink · Dir 860l Firmware

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

9.8 CVSS 3.1 Critical EPSS 0.78% · top 46.0% CWE-798 · Hard-coded credentials
9.8CVSS 3.1 base score
0.78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-41611 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-6530D-Link DIR router soap.cgi OS command injectionsoap.cgi (soapcgi_main in cgibin) on several D-Link DIR router models fails to sanitize the service parameter, allowing OS command injection. The fla…KEVEPSS 97%analysed9.8CVE-2024-42812Dlink dir-860l firmware classic buffer overflow vulnerabilityIn D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID field in gena.cgi. Attackers wh…EPSS 16%9.8CVE-2018-20114Dlink dir-818lw firmware os command injection vulnerabilityOn D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service…EPSS 6.7%6.5CVE-2024-37605Dlink dir-860l firmware null pointer dereference vulnerabilityA NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP requ…EPSS 0.67%6.1CVE-2020-25786Dlink dir-803 firmware cross-site scripting vulnerabilitywebinc/js/info.php on D-Link DIR-816L 2.06.B09_BETA and DIR-803 1.04.B02 devices allows XSS via the HTTP Referer header. NOTE: This vulnerability onl…EPSS 0.99%6.1CVE-2018-6527Dlink dir-860l firmware cross-site scripting vulnerabilityXSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIR…EPSS 1.6%6.1CVE-2018-6528Dlink dir-860l firmware cross-site scripting vulnerabilityXSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE…EPSS 1.6%6.1CVE-2018-6529Dlink dir-860l firmware cross-site scripting vulnerabilityXSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2024-41611), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.