First published: Mon Apr 20 2020(Updated: )
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DSL-2640B Firmware | =eu_4.01b | |
Dlink Dsl-2640b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9277 is rated as a high severity vulnerability due to its ability to allow unauthorized administrative access.
To fix CVE-2020-9277, update the D-Link DSL-2640B firmware to the latest version provided by the manufacturer.
CVE-2020-9277 specifically affects D-Link DSL-2640B B2 EU_4.01B devices.
An attacker exploiting CVE-2020-9277 can bypass authentication and perform administrative tasks, including changing the admin password.
CVE-2020-9277 is not relevant for recent firmware versions if they have been properly updated to address this vulnerability.