D-Link DAP-1325 firmware version 1.01 contains a broken...
High severity
Unreviewed
Published
Dec 16, 2025
to the GitHub Advisory Database
•
Updated Dec 16, 2025
Description
Published by the National Vulnerability Database
Dec 16, 2025
Published to the GitHub Advisory Database
Dec 16, 2025
Last updated
Dec 16, 2025
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
References