CVE-2025-71057
8.2D-Link · Wireless N 300 ADSL2+ Modem Router DSL-124
A vulnerability in the D-Link DSL-124 router allows unauthenticated attackers to perform session hijacking by spoofing the IP address of an authenticated user.
Executive summary
A critical session management flaw in the D-Link Wireless N 300 ADSL2+ Modem Router (DSL-124) exposes users to unauthorized session hijacking and potential account takeover.
Vulnerability
The device suffers from improper session management, which permits an unauthenticated attacker to hijack active sessions by spoofing the IP address of a legitimate, authenticated user.
Business impact
The ability for an unauthenticated remote attacker to hijack administrative or user sessions poses a severe threat to network integrity and confidentiality. With a CVSS score of 8.2, this vulnerability facilitates unauthorized access to router settings, which could lead to traffic interception, credential theft, or complete compromise of the local network perimeter.
Remediation
Immediate Action: Contact D-Link support or check the official D-Link security bulletin portal for the latest firmware release addressing this session management flaw.
Proactive Monitoring: Review device access logs for frequent, unauthorized IP address changes or multiple concurrent sessions originating from different source addresses for the same user profile.
Compensating Controls: Implement strict network segmentation and restrict management interface access to a trusted, internal-only IP range to minimize exposure to external spoofing attempts.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists as referenced in the GitHub repository provided in the vulnerability disclosures.
Analyst recommendation
Given the high CVSS severity and the availability of a public proof-of-concept, users of the D-Link DSL-124 should prioritize the identification of current firmware versions. If a patch is not yet available from the vendor, isolate the management interface of the router from the public internet immediately to prevent remote session hijacking attempts.