ZDI-23-628: D-Link DIR-2150 HNAP Incorrect Implementation of Authentication Algorithm Authentication Bypass Vulnerability
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2150 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-628?
The severity of ZDI-23-628 is classified as high due to the potential for authentication bypass.
How do I fix ZDI-23-628?
To fix ZDI-23-628, update the firmware of your D-Link DIR-2150 router to the latest version provided by the manufacturer.
Who is affected by ZDI-23-628?
ZDI-23-628 affects all installations of the D-Link DIR-2150 router that have not been updated to a secure firmware version.
Can ZDI-23-628 be exploited remotely?
No, ZDI-23-628 requires network-adjacent access, meaning an attacker must be on the same network to exploit the vulnerability.
What is the nature of ZDI-23-628?
ZDI-23-628 is an authentication bypass vulnerability that allows attackers to access the router without authentication.