← back
CVE-2024-11068criticalCWE-648

D-Link DSL6740C - Incorrect Use of Privileged APIs

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 1.2%
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attackers to modify any user’s password by leveraging the API, thereby granting access to Web, SSH, and Telnet services using that user’s account.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
D-Link · DSL6740C