CVE-2024-11065 is an OS Command Injection vulnerability affecting D-Link DSL6740C modems, allowing remote attackers with administrator privileges to execute arbitrary system commands via SSH and Telnet. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating a high impact on confidentiality, integrity, and availability, with a network attack vector and low attack complexity once administrative access is obtained. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, notably regarding D-Link's decision not to patch end-of-life devices. Its EPSS score is low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:dlink:dsl6740c_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.