CVE-2020-24581: OS Command Injection
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU2.31V1.1.47ae55. It contains an executecmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24581?
CVE-2020-24581 is considered a high-severity vulnerability due to its capability of allowing authenticated users to execute arbitrary Operating System commands.
How do I fix CVE-2020-24581?
To mitigate CVE-2020-24581, upgrade your D-Link DSL-2888A firmware to version AU_2.31_V1.1.47ae55 or later.
Who is affected by CVE-2020-24581?
Users of D-Link DSL-2888A devices running firmware prior to AU_2.31_V1.1.47ae55 are affected by CVE-2020-24581.
What is the exploit vector for CVE-2020-24581?
CVE-2020-24581 can be exploited through the execute_cmd.cgi feature, which requires user authentication to access.
Is there a patch available for CVE-2020-24581?
Yes, a patch is available in the form of a firmware update to AU_2.31_V1.1.47ae55 or subsequent versions.