CVE-2020-9275: Critical severity d-link dsl-2640b firmware vulnerability
Published Apr 20, 2020
·Updated
An issue was discovered on D-Link DSL-2640B B2 EU4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.
Affected Software
2 affected components
Dlink Dsl-2640b Firmware=eu_4.01b
Dlink Dsl-2640b
Event History
Apr 20, 2020
CVE Published
via MITRE·10:39 PM
Data Sourced
via MITRE·10:39 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-9275?
CVE-2020-9275 has a high severity level due to the remote, unauthenticated access it allows for credential exfiltration.
2
How do I fix CVE-2020-9275?
To mitigate CVE-2020-9275, it is recommended to update the D-Link DSL-2640B device firmware to the latest version provided by D-Link.
3
What devices are affected by CVE-2020-9275?
CVE-2020-9275 affects the D-Link DSL-2640B device operating on firmware version eu_4.01b.
4
What type of attack does CVE-2020-9275 facilitate?
CVE-2020-9275 facilitates remote, unauthenticated credential exfiltration through a UDP service.
5
Is there a specific port involved in CVE-2020-9275?
Yes, CVE-2020-9275 involves a vulnerable UDP service listening on port 65002.