CVE-2023-37325
Last modified
CVE-2023-37325 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
D-Link DAP-2622 DDP Set SSID List Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to make unauthorized changes to device configuration on affected installations of D-Link DAP-2622 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DDP service. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to manipulate wireless authentication settings. . Was ZDI-CAN-20104.
Metrics
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dap-2622 Firmware | 1.00 |
References
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10349Product, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-23-1280/Third Party Advisory
- https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10349Product, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-23-1280/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2023-37325?
How severe is CVE-2023-37325?
How do I fix CVE-2023-37325?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3732Out of bounds memory access in Mojo in Google Chrome prior t…8.8
- CVE-2023-37320D-Link DAP-2622 DDP Set SSID List SSID Name Stack-based Buff…8.8
- CVE-2023-37321D-Link DAP-2622 DDP Set SSID List RADIUS Secret Stack-based …8.8
- CVE-2023-37322D-Link DAP-2622 DDP Set SSID List RADIUS Server Stack-based …8.8
- CVE-2023-37323D-Link DAP-2622 DDP Set SSID List PSK Stack-based Buffer Ove…8.8
- CVE-2023-37324D-Link DAP-2622 DDP Set Wireless Info Auth Username Stack-ba…8.8
- CVE-2023-37326D-Link DAP-2622 DDP Set Wireless Info Auth Password Stack-ba…8.8
- CVE-2023-37327GStreamer FLAC File Parsing Integer Overflow Remote Code Exe…8.8
- CVE-2023-37328GStreamer PGS File Parsing Heap-based Buffer Overflow Remote…8.8
- CVE-2023-37329GStreamer SRT File Parsing Heap-based Buffer Overflow Remote…8.8
- CVE-2023-3733Inappropriate implementation in WebApp Installs in Google Ch…4.3
- CVE-2023-37330Kofax Power PDF exportAsText Exposed Dangerous Method Remote…7.8
Are you affected by CVE-2023-37325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
