Unrated severityNVD Advisory· Published Dec 16, 2025· Updated Apr 7, 2026
D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download
CVE-2023-53896
Description
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
Affected products
2- D-Link/DAP-1325v5Range: 1.01
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51556mitreexploit
- www.vulncheck.com/advisories/d-link-dap-hardware-a-unauthenticated-configuration-downloadmitrethird-party-advisory
- www.dlink.com/hr/hr/products/dap-1325-n300-wifi-range-extendermitreproduct
News mentions
0No linked articles in our index yet.