CVE-2024-11064 describes an OS Command Injection vulnerability in the D-Link DSL6740C modem, allowing remote attackers with administrator privileges to execute arbitrary system commands via SSH and Telnet. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating a significant risk due to its network-based attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability impacts. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) or KEV entry, the vulnerability has garnered some community discussion and media attention, with D-Link reportedly not planning to patch the end-of-life device.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dsl6740c_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.