ZDI-23-1323: D-Link DAP-1325 CGI Missing Authentication Information Disclosure Vulnerability
Published Sep 7, 2023
·Updated
This vulnerability allows network-adjacent attackers to access various functionality on affected installations of D-Link DAP-1325 routers. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
D-Link DAP-1325
Event History
Sep 7, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
May 3, 2024
Advisory Published
via ZDI·02:25 AM
Frequently Asked Questions
1
What is the severity of ZDI-23-1323?
The severity of ZDI-23-1323 is classified as critical due to lack of authentication required for exploitation.
2
How do I fix ZDI-23-1323?
To fix ZDI-23-1323, install the latest firmware update from D-Link for the DAP-1325 router.
3
Who is affected by ZDI-23-1323?
ZDI-23-1323 affects installations of D-Link DAP-1325 routers that have not been updated.
4
What types of attacks can be executed due to ZDI-23-1323?
Network-adjacent attackers can exploit ZDI-23-1323 to gain unauthorized access to various functionalities of the affected devices.
5
Is authentication required to exploit ZDI-23-1323?
No, authentication is not required to exploit ZDI-23-1323, making it particularly dangerous.