#VU49092 Session fixation in DSL-2888A - CVE-2020-24579
Published: December 18, 2020
DSL-2888A
D-Link
Description
The vulnerability allows a remote attacker to gain unauthorized access to the device.
The vulnerability exists due to incorrect session management mechanism, which solely relies on the user's IP address. A remote attacker with ability to use the victim's IP address can gain unauthorized access to victim's session, after victim successfully logs in onto the device.