PT-2020-5616 · D Link · D-Link Dsl-2888A

Harold Zang

·

Published

2020-05-26

·

Updated

2023-04-26

·

CVE-2020-24580

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DSL-2888A versions prior to AU 2.31 V1.1.47ae55
Description The issue is related to a lack of authentication functionality, allowing an attacker to assign a static IP address that was once used by a valid user. This can potentially lead to IP spoofing attacks. The vulnerability can be exploited remotely.
Recommendations For D-Link DSL-2888A versions prior to AU 2.31 V1.1.47ae55, update the firmware to AU 2.31 V1.1.47ae55 or later to resolve the issue. As a temporary workaround, consider restricting access to the static IP address assignment feature until a patch is available.

Exploit

Fix

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2021-01271
CVE-2020-24580

Affected Products

D-Link Dsl-2888A