CVE-2020-24376

CRITICAL

Freebox Server <4.2.3 - DNS Rebinding in UPnP IGD

Title source: manual
STIX 2.1

Description

A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://dev.freebox.fr/blog/?p=10222

Scores

CVSS v3 9.6
EPSS 0.0100
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (5)
free/freebox_delta_firmware < 4.2.3
free/freebox_mini_firmware < 4.2.3
free/freebox_one_firmware < 4.2.3
free/freebox_pop_firmware < 4.2.3
free/freebox_revolution_firmware < 4.2.3
Published Sep 16, 2020
Tracked Since Feb 18, 2026