CVE-2023-53974

HIGH

D-Link DSL-124 ME_1.00 - Info Disclosure

Title source: llm

Description

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.

Exploits (1)

exploitdb WORKING POC
by Aryan Chehreghani · textremotehardware
https://www.exploit-db.com/exploits/51129

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 28.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-306
Status published

Affected Products (1)

dlink/dsl-124_firmware

Timeline

Published Dec 22, 2025
Tracked Since Feb 18, 2026