CVE-2020-26567
D-Link DSR-250N 3.12 - Denial of Service (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.
Se detectó un problema en los dispositivos D-Link DSR-250N versiones anteriores a 3.17B. Se puede acceder al script CGI upgradeStatusReboot.cgi sin autenticación. Cualquier acceso reinicia el dispositivo, haciéndolo por lo tanto inutilizable durante varios minutos
RedTeam Pentesting discovered a denial of service vulnerability in the D-Link DSR-250N device which allows unauthenticated attackers in the same local network to execute a CGI script that reboots the device. Version 3.12 is confirmed affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-10-05 CVE Reserved
- 2020-10-08 CVE Published
- 2020-10-08 First Exploit
- 2024-08-04 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/48863 | 2020-10-08 | |
http://packetstormsecurity.com/files/159516/D-Link-DSR-250N-Denial-Of-Service.html | 2024-08-04 | |
http://seclists.org/fulldisclosure/2020/Oct/14 | 2024-08-04 | |
https://www.redteam-pentesting.de/advisories/rt-sa-2020-002 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dlink Search vendor "Dlink" | Dsr-250n Firmware Search vendor "Dlink" for product "Dsr-250n Firmware" | < 3.17b Search vendor "Dlink" for product "Dsr-250n Firmware" and version " < 3.17b" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dsr-250n Search vendor "Dlink" for product "Dsr-250n" | - | - |
Safe
|