CVE-2020-24579: High severity d-link dsl-2888a firmware vulnerability
Published Dec 22, 2020
·Updated
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU2.31V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
Affected Software
2 affected components
Dlink Dsl2888a Firmware<au_2.31_v1.1.47ae55
Dlink Dsl2888a
Event History
Dec 22, 2020
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24579?
The severity of CVE-2020-24579 is rated as high with a score of 8.8.
2
How can an unauthenticated attacker exploit CVE-2020-24579?
An unauthenticated attacker could bypass authentication to access authenticated pages and functionality on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55.
3
How can I check if my D-Link DSL-2888A device is affected by CVE-2020-24579?
If your D-Link DSL-2888A device has a firmware version prior to AU_2.31_V1.1.47ae55, it may be affected by CVE-2020-24579.
4
Is there a patch available to fix CVE-2020-24579?
Ensure that you update your D-Link DSL-2888A device to firmware version AU_2.31_V1.1.47ae55 or later to mitigate the vulnerability.