CVE-2024-5294 is a memory leak denial-of-service vulnerability affecting D-Link DIR-3040 routers, specifically within the prog.cgi program's handling of HNAP requests. This flaw, stemming from improper memory management of HTTP cookie values, allows unauthenticated, network-adjacent attackers to trigger a denial-of-service condition. Rated with a CVSS score of 6.5 (Medium), it requires low attack complexity and no user interaction, impacting availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
120b03CPE matchmatch criteria | cpe:2.3:o:dlink:dir-3040_firmware:120b03:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.