CVE-2020-25759: Input Validation
Published Dec 15, 2020
·Updated
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.
Affected Software
20 affected components
Dlink Dsr-150 Firmware<=3.17
Dlink Dsr-150
Dlink Dsr-150n Firmware<=3.17
Dlink Dsr-150n
Dlink Dsr-250 Firmware<=3.17
Dlink Dsr-250
Dlink Dsr-250n Firmware<=3.17
Dlink Dsr-250n
Dlink Dsr-500 Firmware<=3.17
Dlink Dsr-500
Dlink Dsr-500n Firmware
Dlink Dsr-500n
Dlink Dsr-500ac Firmware<=3.17
Dlink Dsr-500ac
Dlink Dsr-1000 Firmware<=3.17
Dlink Dsr-1000
Dlink Dsr-1000n Firmware<=3.17
Dlink Dsr-1000n
Dlink Dsr-1000ac Firmware<=3.17
Dlink Dsr-1000ac
Event History
Dec 15, 2020
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue on D-Link DSR-250 devices?
The vulnerability ID is CVE-2020-25759.
2
What is the severity score of CVE-2020-25759?
The severity score of CVE-2020-25759 is 8.8 (Critical).
3
Which devices are affected by CVE-2020-25759?
D-Link DSR-250 devices with firmware version up to 3.17 are affected.
4
How can an attacker exploit CVE-2020-25759?
An authenticated attacker can exploit CVE-2020-25759 by executing arbitrary commands through the web interface of the Unified Services Router.
5
Are there any available fixes for CVE-2020-25759?
Please refer to the official D-Link security bulletin (link provided) for available fixes and updates.