logo

D-Link fixes critical RCE, hardcoded password flaws in WiFi 6 routers

ID: 4175ab9b-e1c8-5371-b5df-49b027064cd7

STIX ID: report--4175ab9b-e1c8-5371-b5df-49b027064cd7

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-09-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

D-Link released patches for five vulnerabilities (CVE-2024-45694 through CVE-2024-45698) impacting COVR-X1870, DIR‑X4860 and DIR‑X5460 routers — including multiple critical (CVSS 9.8) stack-based buffer overflows enabling unauthenticated remote code execution and telnet flaws that allow access via hard-coded credentials; users should upgrade to the vendor firmware versions listed to mitigate risk, and no active exploitation has been reported in the bulletin.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.