Unauthorized Configuration Changes via DDP Service
CVE-2023-37325
5.4MEDIUM
Summary
The D-Link DAP-2622 router contains a significant security oversight within its DDP service that permits unauthorized users to access and alter device configurations. This vulnerability stems from the absence of necessary authentication checks, enabling attackers situated on the same network to exploit this flaw. By doing so, they can manipulate critical settings, including wireless authentication parameters, posing serious risks to the integrity and security of the network. It is crucial for users of D-Link DAP-2622 devices to stay informed about this issue and take preventive actions to secure their configurations.
Affected Version(s)
DAP-2622 1.00 dated 16-12-2020
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved