#VU27055 Information disclosure in DSL-2640B - CVE-2020-9275
Published: April 21, 2020 / Updated: April 21, 2020
DSL-2640B
D-Link
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to and error in a cfm UDP service listening on port 65002. A remote attacker on the local network can send a specific UDP packet and cause unauthenticated exfiltration of administrative credentials.
This vulnerability affects devices with the following versions:
- Hardware version: B2
- Firmware version: ver.4.01