D-Link DIR-2640 HNAP PrivateLogin Authentication Bypass Vulnerability
CVE-2023-32148
What is CVE-2023-32148?
A significant vulnerability exists in the D-Link DIR-2640 routers, allowing network-adjacent attackers to bypass authentication mechanisms due to flaws in the web management interface. By sending a specially crafted XML element during the login request, an attacker can gain access without the need for valid credentials. This situation poses a risk as it enables unauthorized users to exploit the device's administrative capabilities without hindrance. The vulnerability propagates through the default TCP port 80, making affected routers particularly susceptible if not properly secured.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DIR-2640 1.11B02 (non-US, CA version)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved