CVE-2020-26567: Medium severity d-link dsr-250n firmware vulnerability
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-26567.
What is the severity of CVE-2020-26567?
The severity of CVE-2020-26567 is medium with a CVSS score of 5.5.
What is the description of CVE-2020-26567?
CVE-2020-26567 is a vulnerability discovered on D-Link DSR-250N devices before version 3.17B. The CGI script upgradeStatusReboot.cgi can be accessed without authentication, allowing any user to reboot the device, rendering it unusable for several minutes.
How can I fix CVE-2020-26567?
Upgrade your D-Link DSR-250N firmware to version 3.17B or later to fix CVE-2020-26567.
Are all D-Link DSR-250N devices affected by CVE-2020-26567?
No, only D-Link DSR-250N devices before version 3.17B are affected by CVE-2020-26567.