cve/2020/CVE-2020-25758.md
2024-06-09 00:33:16 +00:00

837 B

CVE-2020-25758

Description

An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into saved configurations before uploading. These entries are executed as root.

POC

Reference

Github

No PoCs found on GitHub currently.