High severity7.5NVD Advisory· Published Dec 16, 2025· Updated Jun 17, 2026
CVE-2023-53896
CVE-2023-53896
Description
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:dlink:dap-1325_firmware:1.01:*:*:*:*:*:*:*
- Range: 1.01
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51556nvdExploit
- www.vulncheck.com/advisories/d-link-dap-hardware-a-unauthenticated-configuration-downloadnvdBroken LinkThird Party Advisory
- www.dlink.com/hr/hr/products/dap-1325-n300-wifi-range-extendernvdProduct
News mentions
0No linked articles in our index yet.