First published: Mon Apr 20 2020(Updated: )
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. The device can be reset to its default configuration by accessing an unauthenticated URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DSL-2640B Firmware | =eu_4.01b | |
Dlink Dsl-2640b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9278 has a severity level that indicates a significant risk due to its ability to allow unauthorized configuration resets.
To fix CVE-2020-9278, you should update the firmware of the D-Link DSL-2640B to the latest version that addresses this vulnerability.
CVE-2020-9278 specifically affects D-Link DSL-2640B devices running the firmware version eu_4.01b.
The nature of the vulnerability in CVE-2020-9278 is that it allows an attacker to reset the device to its default configuration via an unauthenticated URL.
Yes, CVE-2020-9278 can be exploited remotely as it does not require authentication to reset the device.