CVE-2024-41611: D-Link Dir-860l Firmware

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

Affected products

  • D-Link Dir-860l Firmware: version 1.10b04 only

Published 2024-07-30. Last modified 2026-06-17.