Description
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an authenticated user execute Operating System commands.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:19:07.886Z
Reserved: 2020-08-21T00:00:00.000Z
Link: CVE-2020-24581
No data.
Status : Modified
Published: 2020-12-22T19:15:13.347
Modified: 2024-11-21T05:15:02.750
Link: CVE-2020-24581
No data.
OpenCVE Enrichment
No data.
Weaknesses