Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:h:dlink:dap-1325:a1:*:*:*:*:*:*:* |
Wed, 24 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink dap-1325 Firmware
|
|
| CPEs | cpe:2.3:h:dlink:dap-1325:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dap-1325_firmware:1.01:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink dap-1325 Firmware
|
Wed, 17 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dap-1325 |
|
| Vendors & Products |
Dlink
Dlink dap-1325 |
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script. | |
| Title | D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:07:20.166Z
Reserved: 2025-12-16T00:10:40.313Z
Link: CVE-2023-53896
Updated: 2025-12-16T21:44:48.853Z
Status : Analyzed
Published: 2025-12-16T18:16:06.537
Modified: 2025-12-24T17:15:32.207
Link: CVE-2023-53896
No data.
OpenCVE Enrichment
Updated: 2025-12-17T14:29:06Z