CVE-2023-53896
7.5D-Link · DAP-1325
A broken access control vulnerability in D-Link DAP-1325 firmware version 1.01 allows unauthenticated attackers to download device configuration settings via the /cgi-bin/ExportSettings.sh endpoint.
Executive summary
The D-Link DAP-1325 range extender is vulnerable to an unauthenticated configuration disclosure flaw that exposes sensitive device settings to remote attackers.
Vulnerability
The device suffers from missing authentication for a critical function (CWE-306). An unauthenticated attacker can retrieve the device configuration by directly accessing the /cgi-bin/ExportSettings.sh script.
Business impact
Successful exploitation allows an attacker to obtain sensitive configuration data, which may include credentials, wireless keys, or network topology details. This unauthorized access compromises the confidentiality of the device, potentially facilitating further network attacks or unauthorized entry into the local wireless environment. With a CVSS score of 7.5, this high-severity vulnerability represents a significant risk to the integrity of the home or small office network.
Remediation
Immediate Action: Since a specific patch is currently unknown, administrators should restrict network access to the management interface of the device and disable remote management features where possible.
Proactive Monitoring: Review access logs for frequent or unauthorized requests to the /cgi-bin/ExportSettings.sh endpoint, which may indicate reconnaissance or exploitation attempts.
Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring that only trusted internal IP addresses can reach the range extender.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via ExploitDB (ID 51556).
Analyst recommendation
Given the availability of a functional exploit and the ease of access to sensitive configuration files, this vulnerability should be treated with high priority. Users are urged to monitor D-Link support channels for firmware updates and to ensure that the device management interface is not exposed to the public internet until a vendor-supplied patch is applied.
More D-Link CVEs
Sources
Originally found and disclosed by ieduardogoncalves, per the CVE Program record.
- ExploitDB-51556 Exploit / PoC
- D-Link DAP-1325 Product Webpage
- VulnCheck Advisory: D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download Third-party advisory