ZDI-23-1280: D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability
This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-1280?
The severity of ZDI-23-1280 is high due to its potential for unauthorized configuration changes without authentication.
How do I fix ZDI-23-1280?
To fix ZDI-23-1280, users should update their D-Link DAP-2622 routers to the latest firmware version provided by D-Link.
Who is affected by ZDI-23-1280?
ZDI-23-1280 affects installations of D-Link DAP-2622 routers that are exposed to network-adjacent attackers.
Can ZDI-23-1280 be exploited remotely?
No, ZDI-23-1280 can only be exploited by attackers on the same local network as the affected devices.
What kind of changes can be made due to ZDI-23-1280?
ZDI-23-1280 allows attackers to make unauthorized changes to the configuration settings of affected D-Link DAP-2622 routers.