PT-2020-13803 · D Link · D-Link Dsl 2730-U+1

Published

2020-06-08

·

Updated

2021-04-23

·

CVE-2020-13960

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions D-Link DSL 2730-U versions IN 1.10 through IN 1.11 D-Link DIR-600M version 3.04
Description The issue allows remote attackers to provide valid DNS responses for names that would have otherwise resulted in an NXDOMAIN error. This is possible by registering a subdomain of the domain.name domain name, which is included in the DNS resolver search path by default. Attackers can also offer Internet services such as HTTP for these names.
Recommendations For D-Link DSL 2730-U versions IN 1.10 through IN 1.11, remove the domain.name string from the DNS resolver search path. For D-Link DIR-600M version 3.04, remove the domain.name string from the DNS resolver search path. As a temporary workaround, consider restricting access to the DNS resolver to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-13960

Affected Products

D-Link Dir-600
D-Link Dsl 2730-U