First published: Thu Oct 08 2020(Updated: )
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dsr-250n Firmware | <3.17b | |
Dlink Dsr-250n |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-26567.
The severity of CVE-2020-26567 is medium with a CVSS score of 5.5.
CVE-2020-26567 is a vulnerability discovered on D-Link DSR-250N devices before version 3.17B. The CGI script upgradeStatusReboot.cgi can be accessed without authentication, allowing any user to reboot the device, rendering it unusable for several minutes.
Upgrade your D-Link DSR-250N firmware to version 3.17B or later to fix CVE-2020-26567.
No, only D-Link DSR-250N devices before version 3.17B are affected by CVE-2020-26567.