CVE-2023-53974
EUVD-2023-6023622.12.2025, 22:16
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dlink | dsl-124_firmware | 1.00 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References