ZDI-23-544: D-Link DIR-2640 HNAP LoginPassword Authentication Bypass Vulnerability
Published May 4, 2023
·Updated
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
D-Link DIR-2640
Event History
May 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 21, 2025
Advisory Published
via ZDI·07:27 PM
Frequently Asked Questions
1
What is the severity of ZDI-23-544?
The vulnerability ZDI-23-544 has a high severity rating as it allows network-adjacent attackers to bypass authentication.
2
How do I fix ZDI-23-544?
To fix ZDI-23-544, update the firmware of your D-Link DIR-2640 router to the latest version as provided by the manufacturer.
3
Who is affected by ZDI-23-544?
ZDI-23-544 affects installations of D-Link DIR-2640 routers that have not been updated with the latest firmware.
4
What can attackers do with ZDI-23-544?
Attackers exploiting ZDI-23-544 can bypass authentication, potentially gaining unauthorized access to network resources.
5
Is authentication required to exploit ZDI-23-544?
No, authentication is not required to exploit the ZDI-23-544 vulnerability.