Vulnerability Details CVE-2020-26567
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.129
EPSS Ranking 93.7%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.9
Products affected by CVE-2020-26567
-
cpe:2.3:h:dlink:dsr-250n:-
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.01b46
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.01b56
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.05b20
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.05b53
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.05b73_ww
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.08b31
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.08b39
-
cpe:2.3:o:dlink:dsr-250n_firmware:1.08b44
-
cpe:2.3:o:dlink:dsr-250n_firmware:3.11
-
cpe:2.3:o:dlink:dsr-250n_firmware:3.12_ww
-
cpe:2.3:o:dlink:dsr-250n_firmware:3.13_ww
-
cpe:2.3:o:dlink:dsr-250n_firmware:3.14
-
cpe:2.3:o:dlink:dsr-250n_firmware:3.17