D -Link has patched critical vulnerabilities in three popular wireless router modelsthat could allow remote attackers to execute code or gain access to the devices using hardcoded credentials. The affected models are popular, especially among users looking for high-end WiFi 6 routers (DIR-X) and mesh networking systems (COVR).

There are five vulnerabilities (three critical), in the following firmware: COVR-X1870 (outside the US) firmware versions v1.02 and later, DIR-X4860 (worldwide) v1.04B04_Hot-Fix and earlier versions, and DIR-X5460 (worldwide) with firmware v1.11B01_Hot-Fix or earlier.
See also: D-Link: Will not fix new vulnerabilities in DIR-846W router
The five vulnerabilities are as follows:
CVE-2024-45694 (9.8/10): Stack-based buffer overflow vulnerability, which allows remote unauthorized attackers to execute arbitrary code on the device.
CVE-2024-45695 (9.8/10): Similar vulnerability, allowing unauthenticated remote attackers to execute arbitrary code.
CVE-2024-45697 (9.8/10): The Telnet service is enabled when the WAN port is connected, allowing remote access with hard-coded credentials.
CVE-2024-45696 (8.8/10): Attackers can enable the telnet service using hard-coded credentials within the local network.
CVE-2024-45698 (8.8/10): Incorrect login validation in the telnet service allows remote attackers to connect and execute operating system commands with hard-coded credentials.
D-Link is patching the vulnerabilities in the following versions: v1.03B01 for COVR-X1870, v1.04B05 for DIR-X4860, and DIR-X5460A1_V1.11B04 for DIR-X5460. Users and organizations are urged to update systems to stay secure.
See also: Hackers exploit vulnerability in D-Link DIR-859 routers

In addition to the vulnerabilities above, it's important for users of any wireless router to be aware of the potential risks and take steps to secure their network. This includes using strong passwords ,keeping firmware up-to-date, and considering additional security measures, such as setting up a guest network or using a virtual private network (VPN) when accessing sensitive information over public Wi-Fi.
Another aspect of network security that is often overlooked is physical security. It is important to keep routers in a secure location, away from unauthorized people.
See also: Critical vulnerability puts D-Link routers at risk
Additionally, users should be wary of suspicious emails or messages that may contain links or attachments designed to exploit vulnerabilities in routers. It is important to be cautious when clicking on unknown links and never open attachments from untrusted sources.
Source: www.bleepingcomputer.com
