CVE-2020-24578: Medium severity d-link dsl-2888a firmware vulnerability
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU2.31V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24578?
CVE-2020-24578 is considered a high-severity vulnerability due to the exposure of sensitive files through misconfigured FTP service.
How do I fix CVE-2020-24578?
To fix CVE-2020-24578, update the D-Link DSL-2888A firmware to version AU_2.31_V1.1.47ae55 or later.
What type of attack can be executed leveraging CVE-2020-24578?
An attacker can exploit CVE-2020-24578 to gain unauthorized access to system folders and download sensitive files.
Which devices are affected by CVE-2020-24578?
CVE-2020-24578 affects D-Link DSL-2888A devices running firmware versions prior to AU_2.31_V1.1.47ae55.
What file types can be accessed due to CVE-2020-24578?
CVE-2020-24578 allows access to sensitive files like password hash files through misconfigured FTP access.