PT-2022-6578 · D Link · D-Link Dir-2640

Published

2022-12-22

·

Updated

2025-08-06

·

CVE-2023-32152

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR-2640 (affected versions not specified)
Description This issue allows network-adjacent attackers to bypass authentication on affected installations of D-Link DIR-2640 routers. The flaw exists within the web management interface, which listens on TCP port 80 by default. A specially crafted login request can cause authentication to succeed without providing proper credentials, leveraging the vulnerability to bypass authentication on the system. The issue is related to the LoginPassword parameter in the web management interface.
Recommendations As a temporary workaround, consider restricting access to the web management interface until a patch is available. Avoid using the LoginPassword parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-02606
CVE-2023-32152
ZDI-23-544

Affected Products

D-Link Dir-2640