CVE-2020-26887 describes a DNS Rebinding protection bypass vulnerability affecting FRITZ!OS before version 7.21 on FRITZ!Box devices, specifically mentioning the FRITZ!Box 7490. This high-severity vulnerability (CVSS 7.8) allows an attacker with local access and low privileges to achieve high impact on confidentiality, integrity, and availability. While not listed on CISA's KEV or Hot List, an exploit module for this vulnerability is publicly available on ExploitDB, and it has received some community discussion, though no active exploitation or widespread media coverage has been reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.21CPE matchmatch criteria | cpe:2.3:o:avm:fritz\!box_7490_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.