VYPR
Unrated severityNVD Advisory· Published May 1, 2023· Updated Jan 30, 2025

CVE-2023-30063

CVE-2023-30063

Description

D-Link DIR-890L FW1.10 A1 suffers from an authentication bypass vulnerability in the phpcgi component, allowing unauthenticated attackers to retrieve router credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

D-Link DIR-890L FW1.10 A1 suffers from an authentication bypass vulnerability in the phpcgi component, allowing unauthenticated attackers to retrieve router credentials.

Vulnerability

The D-Link DIR-890L router running firmware version FW1.10 A1 contains an authentication bypass vulnerability in the phpcgi component. This component is responsible for processing requests to .php, .asp, and .txt pages, as well as checking user authorization. By crafting a specially designed request, an attacker can bypass the authorization checks entirely [1]. No special configuration beyond the default firmware is required for the vulnerable code path to be reachable.

Exploitation

An attacker does not need prior authentication or any special network position beyond being able to send HTTP requests to the router's management interface. By crafting a malicious request to the phpcgi handler, the authorization check is bypassed. The attacker can then execute script commands that return the router's login credentials (username and password) [1]. A proof-of-concept exploit script (phpcgi.py) is publicly available [1].

Impact

Successful exploitation allows an unauthenticated attacker to retrieve the router's administrative credentials. This results in a complete compromise of the router's configuration interface, leading to full disclosure of sensitive information (e.g., Wi-Fi passwords, network settings) and potential further attacks on the network [1]. The attacker gains administrative-level access to the device.

Mitigation

D-Link has not released a firmware update for this vulnerability, and the DIR-890L is likely an end-of-life (EOL) product. As of the publication date, no fix is available [2]. Users should consider replacing the router with a supported model that receives security updates. If replacement is not possible, restrict remote administration access and ensure the management interface is not exposed to the internet.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Dlink/DIR-890Lcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = FW1.10 A1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.