CVE-2020-25758

An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.
Configurations

Configuration 1


Information

Published : 2020-12-15 08:15

Updated : 2021-04-23 06:24


NVD link : CVE-2020-25758

Mitre link : CVE-2020-25758

Products Affected
No products.
CWE