CVE-2024-8461 Details
Description
A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component Web Management Interface. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 5, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/leetsun/IoT-Vuls/tree/main/Dlink-dns320/4 | [email protected] | ExploitThird Party Advisory |
| https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10383 | [email protected] | Not Applicable |
| https://vuldb.com/?ctiid.276627 | [email protected] | Permissions Required |
| https://vuldb.com/?id.276627 | [email protected] | Third Party Advisory |
| https://vuldb.com/?submit.401300 | [email protected] | Third Party Advisory |
| https://www.dlink.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dlink dns-320 firmware | 2.02b01 |
CPE
Remediation
| |
| dlink dns-320 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 12, 2024 | Initial Analysis | [email protected] |
| Sep 5, 2024 | New CVE Received | [email protected] |