First published: Thu Mar 05 2020(Updated: )
An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the administrative interface can install firmware of their choice.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-link Dsl-2640b Firmware | =e1_eu_1.01 | |
D-Link DSL-2640B |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9544 is considered a high severity vulnerability due to the lack of authentication checks that allows unauthorized firmware installation.
To fix CVE-2020-9544, update the firmware of the D-Link DSL-2640B device to the latest version that addresses this vulnerability.
CVE-2020-9544 affects users of D-Link DSL-2640B E1 EU_1.01 devices that have not implemented additional security measures.
Attackers exploiting CVE-2020-9544 can install malicious firmware on the device without authentication, potentially taking full control.
No, attackers need access to the administrative interface to exploit CVE-2020-9544, which may include local network access.