First published: Tue Feb 02 2021(Updated: )
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsr-250 Firmware | =3.14 | |
Dlink Dsr-250 | ||
Dlink Dsr-1000n Firmware | =2.11b201 | |
Dlink Dsr-1000n |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-18568 is a command injection vulnerability in the D-Link DSR-250 (3.14) and DSR-1000N (2.11B201) UPnP service.
The severity of CVE-2020-18568 is critical with a severity score of 9.8.
CVE-2020-18568 can be exploited by sending a specially crafted UPnP request, allowing remote command execution.
The D-Link DSR-250 (3.14) and DSR-1000N (2.11B201) devices with UPnP service enabled are affected by CVE-2020-18568.
To fix CVE-2020-18568, update the firmware of the affected D-Link DSR-250 and DSR-1000N devices to the latest version.