Record summary

CVE-2020-24579 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHD-Link DSL 2888a - Authentication Bypass/Remote Command ExecutionCVSS 8.8

D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55 are vulnerable to authentication bypass issues which can lead to remote command execution. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.

Impact

Successful exploitation of this vulnerability could allow an attacker to bypass authentication and execute arbitrary commands on the affected router.

Remediation

Apply the latest firmware update provided by D-Link to fix the vulnerability.

WeaknessesCWE-287
Authorspikpikcu
Template tagscvecve2020dlinkrcevuln
CVSS vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:dlink:dsl2888a_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3