CVE-2020-24580: High severity d-link dsl-2888a firmware vulnerability
Published Dec 22, 2020
·Updated
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU2.31V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.
Affected Software
2 affected components
Dlink Dsl2888a Firmware<au_2.31_v1.1.47ae55
Dlink Dsl2888a
Event History
Dec 22, 2020
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
Description
Frequently Asked Questions
1
What is CVE-2020-24580?
CVE-2020-24580 is a vulnerability found on D-Link DSL-2888A devices that allows an attacker to assign a static IP address without authentication.
2
How severe is CVE-2020-24580?
CVE-2020-24580 has a severity rating of 7.5 (High).
3
How can I mitigate CVE-2020-24580?
To mitigate CVE-2020-24580, ensure that your D-Link DSL-2888A device is updated to firmware version AU_2.31_V1.1.47ae55 or later.