CVE-2020-26567

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/10/2020
Last modified:
26/04/2023

Description

An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dsr-250n_firmware:*:*:*:*:*:*:*:* 3.17b (excluding)
cpe:2.3:h:dlink:dsr-250n:-:*:*:*:*:*:*:*