HIGH🇵🇱 Wersja polska

CVE-2020-13960

CVSS 7.5v3.1pub. 2020-06-08upd. 2024-11-21

D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows remote attackers to provide valid DNS responses (and also offer Internet services such as HTTP) for names that otherwise would have had an NXDOMAIN error, by registering a subdomain of the domain.name domain name.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Dlink Dir 600m

    HW
    Dlink
    all versions
  • Dlink Dir 600m Firmware

    OS
    Dlink
    3.04
  • Dlink Dsl 2730u

    HW
    Dlink
    all versions
  • Dlink Dsl 2730u Firmware

    OS
    Dlink
    in_1.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-13101CRITICAL9.8PL ✓same product

Brak uwierzytelnienia dla strony wan.htm w D-Link DIR-600M

CVE-2019-7736CRITICAL9.8PL ✓same product

D-Link DIR-600M: pominięcie uwierzytelnienia via bezpośrednie żądanie do wan.htm

CVE-2024-1786HIGH7.5same product

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DI...

CVE-2017-9100HIGH8.8same product

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by en...

CVE-2017-5874HIGH8.8same product

CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass aut...