CVE-2023-53896
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
16/12/2025
Last modified:
24/12/2025
Description
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint to retrieve sensitive configuration information by directly accessing the export settings script.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:dlink:dap-1325_firmware:1.01:*:*:*:*:*:*:* | ||
| cpe:2.3:h:dlink:dap-1325:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



