VYPR
Unrated severityNVD Advisory· Published May 10, 2024· Updated Aug 6, 2024

D-Link DAR-8000-10 importhtml.php deserialization

CVE-2024-4699

Description

UNSUPPORTED WHEN ASSIGNED A vulnerability, which was classified as critical, has been found in D-Link DAR-8000-10 up to 20230922. This issue affects some unknown processing of the file /importhtml.php. The manipulation of the argument sql leads to deserialization. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-263747. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.

Affected products

2
  • Dlink/DAR-8000-10llm-create2 versions
    <= 20230922+ 1 more
    • (no CPE)range: <= 20230922
    • (no CPE)range: 20230922

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.