CVE-2020-24579
D-Link DSL 2888a - Authentication Bypass/Remote Command Execution
Record summary
CVE-2020-24579 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHD-Link DSL 2888a - Authentication Bypass/Remote Command ExecutionCVSS 8.8
D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55 are vulnerable to authentication bypass issues which can lead to remote command execution. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication and execute arbitrary commands on the affected router.
Remediation
Apply the latest firmware update provided by D-Link to fix the vulnerability.
Source: ProjectDiscovery