logo

D-Link Routers Vulnerable to Takeover Via Exploit for Zero-Day

ID: 8a4fe5e6-aa69-5ab5-bdf5-be3a345da6f6

STIX ID: report--8a4fe5e6-aa69-5ab5-bdf5-be3a345da6f6

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-05-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers published a proof-of-concept exploit for a zero-day in D-Link DIR-X4860 routers that enables unauthenticated attackers who can reach the HNAP port to bypass authentication and perform command injection in /bin/prog.cgi, leading to root-level takeover; SSD Secure Disclosure reported the issue and publicized the exploit after D-Link failed to respond, and users are advised to disable remote management as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.