Description
D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.
Problem types
Missing Authentication for Critical Function
Product status
Credits
Aryan Chehreghani
References
www.exploit-db.com/exploits/51129
www.exploit-db.com/exploits/51129 (ExploitDB-51129)
www.dlink.com (D-Link Official Homepage)
dlinkmea.com/...details?det=dU1iNFc4cWRsdUpjWEpETFlSeFlZdz09 (D-Link MEA Product Details Page)
www.vulncheck.com/...-disclosure-via-unauthenticated-request (VulnCheck Advisory: D-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated Request)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.