CVE-2020-24377

CRITICAL

Freebox OS < 4.2.3 - DNS Rebinding

Title source: llm
STIX 2.1

Description

A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://dev.freebox.fr/blog/?p=10222
Exploit, Third Party Advisory x_refsource_misc
https://www.gabriel.urdhr.fr/2020/09/23/dns-rebinding-freebox/

Scores

CVSS v3 9.6
EPSS 0.0119
EPSS Percentile 64.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (5)
free/freebox_delta_firmware < 4.2.3
free/freebox_mini_firmware < 4.2.3
free/freebox_one_firmware < 4.2.3
free/freebox_pop_firmware < 4.2.3
free/freebox_revolution_firmware < 4.2.3
Published Sep 16, 2020
Tracked Since Feb 18, 2026