First published: Tue Dec 22 2020(Updated: )
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsl2888a Firmware | <au_2.31_v1.1.47ae55 | |
Dlink Dsl2888a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24578 is considered a high-severity vulnerability due to the exposure of sensitive files through misconfigured FTP service.
To fix CVE-2020-24578, update the D-Link DSL-2888A firmware to version AU_2.31_V1.1.47ae55 or later.
An attacker can exploit CVE-2020-24578 to gain unauthorized access to system folders and download sensitive files.
CVE-2020-24578 affects D-Link DSL-2888A devices running firmware versions prior to AU_2.31_V1.1.47ae55.
CVE-2020-24578 allows access to sensitive files like password hash files through misconfigured FTP access.