VYPR
Unrated severityNVD Advisory· Published Dec 22, 2025· Updated Dec 22, 2025

D-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated Request

CVE-2023-53974

Description

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.

Affected products

2
  • Dlink/DSL-124llm-create
    Range: ME_1.00
  • D-Link/DSL-124 Wireless N300 ADSL2+v5
    Range: ME_1.00

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.