PT-2020-5338 · D Link · Dsr-250N+8
Published
2020-08-11
·
Updated
2021-07-21
·
CVE-2020-25759
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link DSR-250 version 3.17
D-Link DSR-150 (affected versions not specified)
D-Link DSR-150N (affected versions not specified)
D-Link DSR-250N (affected versions not specified)
D-Link DSR-500 (affected versions not specified)
D-Link DSR-500N (affected versions not specified)
D-Link DSR-500AC (affected versions not specified)
D-Link DSR-1000 (affected versions not specified)
D-Link DSR-1000N (affected versions not specified)
D-Link DSR-1000AC (affected versions not specified)
Description
The issue is related to the Unified Services Router web interface, where certain functionality could allow an authenticated attacker to execute arbitrary commands due to a lack of validation of inputs provided in multipart HTTP POST requests. This could potentially allow a remote attacker to elevate their privileges and execute arbitrary code.
Recommendations
For D-Link DSR-250 version 3.17, consider disabling the vulnerable functionality in the Unified Services Router web interface until a patch is available.
For D-Link DSR-150, DSR-150N, DSR-250N, DSR-500, DSR-500N, DSR-500AC, DSR-1000, DSR-1000N, DSR-1000AC, restrict access to the Unified Services Router web interface to minimize the risk of exploitation, as the affected versions are not specified.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dsr-1000
Dsr-1000Ac
Dsr-1000N
Dsr-150
Dsr-250
Dsr-250N
Dsr-500
Dsr-500Ac
Dsr-500N