Vulnerability Details CVE-2023-53974
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.5%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-53974
-
cpe:2.3:h:dlink:dsl-124:r1
-
cpe:2.3:o:dlink:dsl-124_firmware:1.00