Unrated severityNVD Advisory· Published Dec 16, 2025· Updated Apr 7, 2026
D-Link DAP-1325 Hardware A1 Unauthenticated Configuration Download
CVE-2023-53896
Description
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51556mitreexploit
- www.vulncheck.com/advisories/d-link-dap-hardware-a-unauthenticated-configuration-downloadmitrethird-party-advisory
- www.dlink.com/hr/hr/products/dap-1325-n300-wifi-range-extendermitreproduct
News mentions
0No linked articles in our index yet.