PT-2026-3842 · D Link · D-Link D-View 8
Kazuma Matsumoto
·
Published
2026-01-21
·
Updated
2026-01-21
·
CVE-2026-23754
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
D-Link D-View 8 versions 2.0.1.107 and below
Description
D-Link D-View 8 versions 2.0.1.107 and below have an improper access control issue in backend API endpoints. An authenticated user can provide an arbitrary
user id value to obtain sensitive credential data for other users, including super administrators. This credential material can be directly used for authentication, enabling full impersonation of the targeted account and complete administrative control over the D-View system. The vulnerable API endpoints allow unauthorized access to user credentials through manipulation of the user id parameter.Recommendations
Versions prior to 2.0.1.107 should be updated.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
D-Link D-View 8