CVE-2020-24374

CRITICAL

Freebox v5 <1.5.29 - DNS Rebinding

Title source: manual
STIX 2.1

Description

A DNS rebinding vulnerability in Freebox v5 before 1.5.29.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://dev.freebox.fr/blog/?p=10222
Exploit, Third Party Advisory x_refsource_misc
https://www.gabriel.urdhr.fr/2020/09/23/dns-rebinding-freebox/

Scores

CVSS v3 9.6
EPSS 0.0117
EPSS Percentile 63.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
free/freebox_hd_firmware < 1.5.29
Published Sep 16, 2020
Tracked Since Feb 18, 2026