logo

D-Link won’t fix critical bug in 60,000 exposed EoL modems

ID: 03cfb947-1579-566a-8c5c-db530db59988

STIX ID: report--03cfb947-1579-566a-8c5c-db530db59988

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Security researcher Chaio-Lin Yu disclosed multiple critical and high-severity vulnerabilities in the end-of-life D-Link DSL6740C modem — including CVE-2024-11068 (CVSS 9.8) which enables unauthenticated password changes and full device takeover, plus path traversal and OS command injection flaws — while D-Link declined to patch EoL devices; FOFA scans show ~60,000 exposed units, so affected users are advised to retire or isolate these devices and restrict remote access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.