Taiwan’s CERT has warned about a serious security issue with D-Link wireless routers, affecting many models. This vulnerability could let attackers on the local network access the router’s Telnet service using basic administrator credentials
CVE-2024-6045
By infosecbulletin
/ Friday , April 18 2025
According to Shadowserver Foundation around 17,000 Fortinet devices worldwide have been compromised using a new technique called "symlink". This number...
Read More
By infosecbulletin
/ Friday , April 18 2025
A critical security flaw has been found in the Erlang/Open Telecom Platform (OTP) SSH implementation, allowing an attacker to run...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, CISA alerted about increased breach risks due to the earlier compromise of legacy Oracle Cloud servers, emphasizing the...
Read More
By infosecbulletin
/ Thursday , April 17 2025
Cisco issued a security advisory about a serious vulnerability in its Webex App that allows unauthenticated remote code execution (RCE)...
Read More
By infosecbulletin
/ Thursday , April 17 2025
On Wednesday, Apple released urgent operating system updates to address two security vulnerabilities that had already been exploited in highly...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
On April 15, 2025, Oracle released a Critical Patch Update for 378 flaws for its products. The patch update covers...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Check Point Research warns of the active exploitation of a new vulnerability, CVE-2025-24054, which lets hackers leak NTLMv2-SSP hashes using...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
Bengaluru's Whiteboard Technologies Pvt Ltd was hit by a ransomware attack, with hackers demanding a ransom of up to $70,000...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
MITRE Vice President Yosry Barsoum warned that U.S. government funding for the Common Vulnerabilities and Exposures (CVE) and Common Weakness...
Read More
By infosecbulletin
/ Wednesday , April 16 2025
PwC has ceased operations in more than a dozen countries that its global bosses have deemed too small, risky or...
Read More
Certain D-Link router models have a hidden backdoor that was recently discovered. This flaw allows attackers on the same network to gain unauthorized control over the router by accessing a specific URL, enabling the Telnet service, and using administrator credentials obtained from firmware analysis. This poses significant security risks.
The affected D-Link router models are: E15, E30, G403, G415, G416, M15, M18, M30, M32, M60, R03, R04, R12, R15, R18, and R32.
D-Link released firmware updates to fix the CVE-2024-6045 (CVSS 8.8) vulnerability. Users should update their router’s firmware to the specified versions or later.
G403, G415, G416, M18, R03, R04, R12, R18: Update to firmware version 1.10.01 or later.
E30, M30, M32, M60, R32: Update to firmware version 1.10.02 or later.
E15, R15: Update to firmware version 1.20.01 or later.
Ensure the successful update by comparing the router’s displayed firmware version with the downloaded update.
D-Link is working on releasing official firmware updates, but for now, there may be beta versions available. However, users should be careful when using beta software, as it is still being tested and might not be completely stable. D-Link is not responsible for any problems that might occur from using beta firmware.
You can visit D-Link’s website for more info and to download the latest firmware updates.