Dlink Dsl2888A Firmware vulnerabilities
4 known vulnerabilities affecting dlink/dsl2888a_firmware.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-24581HIGHCVSS 8.0Exploitedfixed in au_2.31_v1.1.47ae552020-12-22
CVE-2020-24581 [HIGH] CWE-78 CVE-2020-24581: An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It c
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.
nvd
CVE-2020-24580HIGHCVSS 7.5fixed in au_2.31_v1.1.47ae552020-12-22
CVE-2020-24580 [HIGH] CWE-306 CVE-2020-24580: An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once used by a valid user.
nvd
CVE-2020-24579HIGHCVSS 8.8PoCfixed in au_2.31_v1.1.47ae552020-12-22
CVE-2020-24579 [HIGH] CWE-287 CVE-2020-24579: An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An u
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
nvd
CVE-2020-24578MEDIUMCVSS 6.5fixed in au_2.31_v1.1.47ae552020-12-22
CVE-2020-24578 [MEDIUM] CWE-427 CVE-2020-24578: An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It h
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It has a misconfigured FTP service that allows a malicious network user to access system folders and download sensitive files (such as the password hash file).
nvd