An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rendering it therefore unusable for several minutes.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://www.redteam-pentesting.de/advisories/rt-sa-2020-002 | patch mitigation exploit third party advisory |
http://seclists.org/fulldisclosure/2020/Oct/14 | mailing list patch mitigation exploit third party advisory |
http://packetstormsecurity.com/files/159516/D-Link-DSR-250N-Denial-Of-Service.html | patch mitigation exploit vdb entry third party advisory |