CVE-2023-53896: D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53896?
CVE-2023-53896 has a medium severity rating due to its impact on device security and potential unauthorized access to sensitive information.
How do I fix CVE-2023-53896?
To fix CVE-2023-53896, users should upgrade the firmware of the D-Link DAP-1325 to the latest version provided by the vendor.
What does CVE-2023-53896 affect?
CVE-2023-53896 specifically affects the D-Link DAP-1325 firmware version 1.01, allowing unauthorized access to configuration settings.
What type of vulnerability is CVE-2023-53896?
CVE-2023-53896 is a broken access control vulnerability that allows attackers to retrieve configuration settings without authentication.
Who can exploit CVE-2023-53896?
Any unauthenticated attacker can exploit CVE-2023-53896 to download device configuration settings via the affected endpoint.