CVE-2022-43620
Description
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-1935 1.03 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HNAP login requests. The issue results from the lack of proper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-16142.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Network-adjacent attackers can bypass authentication on D-Link DIR-1935 routers via a flaw in HNAP login handling, allowing full compromise.
Vulnerability
The vulnerability resides in the HNAP PrivateLogin handler of D-Link DIR-1935 routers running firmware version 1.03 (specifically build DIR1935A1_FW1.03B02_Beta_ipv6_default_gateway_20181224.bin [1]). The authentication algorithm is improperly implemented, allowing an unauthenticated attacker to bypass the login process. Affected hardware revision is Ax with firmware v1.03b02 [1].
Exploitation
An attacker must be network-adjacent (i.e., on the same local network or within wireless range) and does not require any prior authentication. The attacker sends a specially crafted HNAP login request to the router's management interface. Due to the flawed authentication algorithm, the request is accepted without proper verification, granting the attacker administrative access [2].
Impact
Successful exploitation allows the attacker to bypass authentication and gain full administrative control over the router. This can lead to disclosure of sensitive configuration data, modification of network settings, and potentially remote code execution as the web server runs with elevated privileges. The CVSS score is 8.8 (High) with impacts on confidentiality, integrity, and availability all rated High [2].
Mitigation
D-Link has issued a firmware update to correct this vulnerability [2]. Users should upgrade to the latest firmware version available from the D-Link support website [1]. No workarounds have been provided. If the device is no longer supported, replacement is recommended.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- D-Link/DIR-1935v5Range: 1.03
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.