ZDI-23-715: D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability
Published May 24, 2023
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
D-Link D-View
Event History
May 24, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Feb 25, 2025
Advisory Published
via ZDI·09:05 PM
Frequently Asked Questions
1
What is the severity of ZDI-23-715?
The severity of ZDI-23-715 is considered high due to the potential for remote attackers to disclose sensitive information without authentication.
2
How do I fix ZDI-23-715?
To fix ZDI-23-715, ensure that your D-Link D-View installation is updated to the latest version provided by the vendor.
3
Are there any prerequisites to exploit ZDI-23-715?
No, ZDI-23-715 can be exploited without any authentication requirements.
4
What information can be disclosed due to ZDI-23-715?
ZDI-23-715 allows remote attackers to access potentially sensitive information from affected installations.
5
Which product is affected by ZDI-23-715?
ZDI-23-715 specifically affects D-Link D-View installations.