CVE-2023-53974: D-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated Request
D-Link DSL-124 ME1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-53974?
CVE-2023-53974 has been rated as a high-severity vulnerability due to its potential for exposing sensitive router configuration files.
How do I fix CVE-2023-53974?
To remediate CVE-2023-53974, ensure that the router is updated to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2023-53974?
CVE-2023-53974 affects D-Link DSL-124 routers that are running unpatched firmware.
What kind of data can be accessed through CVE-2023-53974?
An attacker exploiting CVE-2023-53974 can access the router's configuration settings, which may include sensitive network information.
Can CVE-2023-53974 be exploited remotely?
Yes, CVE-2023-53974 can be exploited by unauthenticated attackers remotely through crafted POST requests.