Description
D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.
Published: 2024-06-27
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Feb 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dir-1950 Firmware
CPEs cpe:2.3:o:d-link:dir-1950_firmware:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-1950 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-1950
Dlink dir-1950 Firmware
CPEs cpe:2.3:h:dlink:dir-1950:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-1950_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-1950
Dlink dir-1950 Firmware

Subscriptions

D-link Dir-1950 Firmware
Dlink Dir-1950 Dir-1950 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T03:37:05.330Z

Reserved: 2024-05-30T00:00:00.000Z

Link: CVE-2024-36755

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:05.330Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-27T21:15:15.700

Modified: 2025-07-09T18:29:22.610

Link: CVE-2024-36755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses