D-Link Routers Vulnerable to Takeover Via Exploit for Zero-Day
ID: 8a4fe5e6-aa69-5ab5-bdf5-be3a345da6f6
STIX ID: report--8a4fe5e6-aa69-5ab5-bdf5-be3a345da6f6
Feed Name: Dark Reading
Date Published: 2024-05-15
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers published a proof-of-concept exploit for a zero-day in D-Link DIR-X4860 routers that enables unauthenticated attackers who can reach the HNAP port to bypass authentication and perform command injection in /bin/prog.cgi, leading to root-level takeover; SSD Secure Disclosure reported the issue and publicized the exploit after D-Link failed to respond, and users are advised to disable remote management as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
