D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-27T00:00:00

Updated: 2024-08-02T03:37:05.330Z

Reserved: 2024-05-30T00:00:00

Link: CVE-2024-36755

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:05.330Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-27T21:15:15.700

Modified: 2024-08-01T13:53:15.830

Link: CVE-2024-36755

cve-icon Redhat

No data.