vendor:
DSR-250N Wireless N Unified Service Router
by:
Kiko Andreu (kikoas1995) & Daniel Monzón (stark0de)
5.5
CVSS
MEDIUM
DoS
N/A
CWE
Product Name: DSR-250N Wireless N Unified Service Router
Affected Version From: 3.12
Affected Version To: 3.17B
Patch Exists: YES
Related CWE: CVE-2020-26567
CPE: h:d-link:dsr-250n_wireless-n_unified_service_router
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
D-Link DSR-250N 3.12 – Denial of Service (PoC)
RedTeam Pentesting discovered a Denial-of-Service vulnerability in the D-Link DSR-250N device which allows unauthenticated attackers in the same local network to execute a CGI script which reboots the device.
Mitigation:
Upgrade to the latest version of the D-Link DSR-250N router (3.17B)