CVE-2020-13960: High severity d-link dsl-2730u firmware vulnerability
D-Link DSL 2730-U IN1.10 and IN1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows remote attackers to provide valid DNS responses (and also offer Internet services such as HTTP) for names that otherwise would have had an NXDOMAIN error, by registering a subdomain of the domain.name domain name.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-13960.
What devices are affected by CVE-2020-13960?
D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices are affected by CVE-2020-13960.
What is the severity level of CVE-2020-13960?
CVE-2020-13960 has a severity level of 7.5, which is considered high.
What is the default vulnerability in D-Link devices?
The default vulnerability in D-Link devices is having the domain.name string in the DNS resolver search path, as seen in CVE-2020-13960.
How can CVE-2020-13960 be exploited?
CVE-2020-13960 can be exploited by remote attackers providing valid DNS responses and offering Internet services such as HTTP for names that would have had an NXDOMAIN error.