CVE-2020-24578
Severity CVSS v4.0:
Pending analysis
Type:
CWE-427
Uncontrolled Search Path Element
Publication date:
22/12/2020
Last modified:
26/04/2023
Description
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
3.30
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dlink:dsl2888a_firmware:*:*:*:*:*:*:*:* | au_2.31_v1.1.47ae55 (excluding) | |
| cpe:2.3:h:dlink:dsl2888a:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



