D-Link DAP-1325
cpe:2.3:h:dlink:dap-1325:*:*:*:*:*:*:*, +1 more
- A1
- 1.01
A broken access control vulnerability has been identified in the D-Link DAP-1325 N300 Wi-Fi Range Extender, specifically in firmware version 1.01. This vulnerability allows unauthenticated attackers to download device configuration settings by exploiting the /cgi-bin/ExportSettings.sh endpoint. The issue arises because the device fails to require proper authentication before allowing access to sensitive configuration information.
Exploitation of this vulnerability could lead to unauthorized access to sensitive device configuration settings, which may include Wi-Fi credentials and other personal information.
To reproduce this vulnerability, access the device's login page and navigate to the /cgi-bin/ExportSettings.sh endpoint. This can be done by directly entering the URL into a web browser. The absence of authentication will allow the configuration settings to be downloaded without any credentials.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.