D-Link DSL-124 ME_1.00 contains a configuration file...
High severity
Unreviewed
Published
Dec 23, 2025
to the GitHub Advisory Database
•
Updated Dec 23, 2025
Description
Published by the National Vulnerability Database
Dec 22, 2025
Published to the GitHub Advisory Database
Dec 23, 2025
Last updated
Dec 23, 2025
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.
References