Description
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.
Exploits (1)
exploitdb
WRITEUP
by RedTeam Pentesting GmbH · textwebappshardware
https://www.exploit-db.com/exploits/48863
References (3)
Scores
CVSS v3
5.5
EPSS
0.2938
EPSS Percentile
96.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-306
Status
published
Products (1)
dlink/dsr-250n_firmware
< 3.17b
Published
Oct 08, 2020
Tracked Since
Feb 18, 2026