CVE-2024-0717 is a critical information disclosure vulnerability affecting numerous D-Link router and modem models, as well as the Good Line Router v2. By manipulating the 'area' argument within an HTTP GET request to the /devinfo component, an unauthenticated attacker can remotely obtain sensitive device information. While the CVSS score is 5.3 (Medium), indicating low complexity and no user interaction, the vulnerability has a high FAUCET Risk Score of 85/100. Although public exploit details exist, there is no evidence of active exploitation, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2024-01-12CPE matchmatch criteria | cpe:2.3:o:dlink:dir-825acg1_firmware:*:*:*:*:*:*:*:* | ||
<= 2024-01-12CPE matchmatch criteria | cpe:2.3:o:dlink:dir-841_firmware:*:*:*:*:*:*:*:* | ||
<= 2024-01-12CPE matchmatch criteria | cpe:2.3:o:dlink:dir-1260_firmware:*:*:*:*:*:*:*:* | ||
<= 2024-01-12CPE matchmatch criteria | cpe:2.3:o:dlink:dir-822_firmware:*:*:*:*:*:*:*:* | ||
<= 2024-01-12CPE matchmatch criteria | cpe:2.3:o:dlink:dir-x1530_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.