CVE-2020-9544: High severity D-Link Dsl-2640b Firmware vulnerability
An issue was discovered on D-Link DSL-2640B E1 EU1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their choice.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9544?
CVE-2020-9544 is considered a high severity vulnerability due to the lack of authentication checks that allows unauthorized firmware installation.
How do I fix CVE-2020-9544?
To fix CVE-2020-9544, update the firmware of the D-Link DSL-2640B device to the latest version that addresses this vulnerability.
Who is affected by CVE-2020-9544?
CVE-2020-9544 affects users of D-Link DSL-2640B E1 EU_1.01 devices that have not implemented additional security measures.
What can attackers do with CVE-2020-9544?
Attackers exploiting CVE-2020-9544 can install malicious firmware on the device without authentication, potentially taking full control.
Is remote access required to exploit CVE-2020-9544?
No, attackers need access to the administrative interface to exploit CVE-2020-9544, which may include local network access.