ZDI-CAN-20104: ZDI-23-1280: D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability
This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20104?
The severity of ZDI-CAN-20104 is considered critical due to its potential for unauthorized device configuration changes by network-adjacent attackers.
How do I fix ZDI-CAN-20104?
To fix ZDI-CAN-20104, update your D-Link DAP-2622 router to the latest firmware version provided by D-Link.
Who is vulnerable to ZDI-CAN-20104?
Any installation of D-Link DAP-2622 routers that has not been updated with the security patch is vulnerable to ZDI-CAN-20104.
What can attackers do with ZDI-CAN-20104?
Attackers exploiting ZDI-CAN-20104 can make unauthorized changes to the device configuration without authentication.
Is authentication required to exploit ZDI-CAN-20104?
No, authentication is not required to exploit ZDI-CAN-20104, making it particularly dangerous.