D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.
References
Link | Resource |
---|---|
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10401 | Vendor Advisory |
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10401 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
09 Jul 2025, 18:29
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dlink
Dlink dir-1950 Firmware Dlink dir-1950 |
|
CPE | cpe:2.3:h:dlink:dir-1950:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dir-1950_firmware:*:*:*:*:*:*:*:* |
|
References | () https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10401 - Vendor Advisory |
Information
Published : 2024-06-27 21:15
Updated : 2025-07-09 18:29
NVD link : CVE-2024-36755
Mitre link : CVE-2024-36755
CVE.ORG link : CVE-2024-36755
JSON object : View
Products Affected
dlink
- dir-1950
- dir-1950_firmware
CWE
CWE-599
Missing Validation of OpenSSL Certificate