nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-53896 CVE-2023-53896
HIGH
D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download
Record summary
CVE-2023-53896 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
DAP-1325Browse D-Link / DAP-1325 | CVE List | 1.01 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBD-Link DAP-1325 - Broken Access ControlExploitDB exploitby ieduardogoncalvesNot analyzed1 file
References
4D-Link DAP-1325 Product Webpageproduct
https://www.dlink.com/hr/hr/products/dap-1325-n300-wifi-range-extender ExploitDB-51556exploit
https://www.exploit-db.com/exploits/51556 VulnCheck Advisory: D-Link DAP-1325 Hardware A1 Unauthenticated Configuration DownloadThird-party advisory
https://www.vulncheck.com/advisories/d-link-dap-hardware-a-unauthenticated-configuration-download