9

CVE-2020-25758

An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.

Data is provided by the National Vulnerability Database (NVD)
DlinkDsr-150 Firmware Version <= 3.17
   DlinkDsr-150 Version-
DlinkDsr-150n Firmware Version <= 3.17
   DlinkDsr-150n Version-
DlinkDsr-250 Firmware Version <= 3.17
   DlinkDsr-250 Version-
DlinkDsr-250n Firmware Version <= 3.17
   DlinkDsr-250n Version-
DlinkDsr-500 Firmware Version <= 3.17
   DlinkDsr-500 Version-
DlinkDsr-500n Firmware
   DlinkDsr-500n Version-
DlinkDsr-500ac Firmware Version <= 3.17
   DlinkDsr-500ac Version-
DlinkDsr-1000 Firmware Version <= 3.17
   DlinkDsr-1000 Version-
DlinkDsr-1000n Firmware Version <= 3.17
   DlinkDsr-1000n Version-
DlinkDsr-1000ac Firmware Version <= 3.17
   DlinkDsr-1000ac Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.31% 0.536
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-354 Improper Validation of Integrity Check Value

The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.