CVE-2023-53896

7.5

D-Link · DAP-1325

A broken access control vulnerability in D-Link DAP-1325 firmware version 1.01 allows unauthenticated attackers to download device configuration settings via the /cgi-bin/ExportSettings.sh endpoint.

Executive summary

The D-Link DAP-1325 range extender is vulnerable to an unauthenticated configuration disclosure flaw that exposes sensitive device settings to remote attackers.

Vulnerability

The device suffers from missing authentication for a critical function (CWE-306). An unauthenticated attacker can retrieve the device configuration by directly accessing the /cgi-bin/ExportSettings.sh script.

Business impact

Successful exploitation allows an attacker to obtain sensitive configuration data, which may include credentials, wireless keys, or network topology details. This unauthorized access compromises the confidentiality of the device, potentially facilitating further network attacks or unauthorized entry into the local wireless environment. With a CVSS score of 7.5, this high-severity vulnerability represents a significant risk to the integrity of the home or small office network.

Remediation

Immediate Action: Since a specific patch is currently unknown, administrators should restrict network access to the management interface of the device and disable remote management features where possible.

Proactive Monitoring: Review access logs for frequent or unauthorized requests to the /cgi-bin/ExportSettings.sh endpoint, which may indicate reconnaissance or exploitation attempts.

Compensating Controls: Implement firewall rules to block external access to the device management interface, ensuring that only trusted internal IP addresses can reach the range extender.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists via ExploitDB (ID 51556).

Analyst recommendation

Given the availability of a functional exploit and the ease of access to sensitive configuration files, this vulnerability should be treated with high priority. Users are urged to monitor D-Link support channels for firmware updates and to ensure that the device management interface is not exposed to the public internet until a vendor-supplied patch is applied.

More D-Link CVEs

Sources

Originally found and disclosed by ieduardogoncalves, per the CVE Program record.