D-Link DIR-1950 up to v1.11B03 does not validate SSL certificates when requesting the latest firmware version and downloading URL. This can allow attackers to downgrade the firmware version or change the downloading URL via a man-in-the-middle attack.
History

Wed, 09 Jul 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dir-1950
Dlink dir-1950 Firmware
CPEs cpe:2.3:h:dlink:dir-1950:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-1950_firmware:*:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dir-1950
Dlink dir-1950 Firmware

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-27T00:00:00

Updated: 2024-08-02T03:37:05.330Z

Reserved: 2024-05-30T00:00:00

Link: CVE-2024-36755

cve-icon Vulnrichment

Updated: 2024-08-02T03:37:05.330Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-27T21:15:15.700

Modified: 2025-07-09T18:29:22.610

Link: CVE-2024-36755

cve-icon Redhat

No data.