First published: Mon Apr 20 2020(Updated: )
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. A cfm UDP service listening on port 65002 allows remote, unauthenticated exfiltration of administrative credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DSL-2640B Firmware | =eu_4.01b | |
Dlink Dsl-2640b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9275 has a high severity level due to the remote, unauthenticated access it allows for credential exfiltration.
To mitigate CVE-2020-9275, it is recommended to update the D-Link DSL-2640B device firmware to the latest version provided by D-Link.
CVE-2020-9275 affects the D-Link DSL-2640B device operating on firmware version eu_4.01b.
CVE-2020-9275 facilitates remote, unauthenticated credential exfiltration through a UDP service.
Yes, CVE-2020-9275 involves a vulnerable UDP service listening on port 65002.