High severity7.5NVD Advisory· Published Dec 22, 2025· Updated Jun 17, 2026
CVE-2023-53974
CVE-2023-53974
Description
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:dlink:dsl-124_firmware:1.00:*:*:*:*:*:*:*
- Range: ME_1.00
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/51129nvdExploit
- www.vulncheck.com/advisories/d-link-dsl-me-backup-configuration-file-disclosure-via-unauthenticated-requestnvdThird Party Advisory
- dlinkmea.com/index.php/product/detailsnvdProduct
- www.dlink.comnvdProduct
News mentions
0No linked articles in our index yet.