PT-2026-22152 · D Link · D-Link Wireless N 300 Adsl2+ Modem Router Dsl-124 Me
CVE-2025-71057
·
Publicado
2026-02-26
·
Atualizado
2026-03-03
CVSS v3.1
8.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME version 1.00
Description
The device suffers from improper session management, which allows attackers to perform a session hijacking attack. This is achieved by spoofing the IP address of an authenticated user.
Recommendations
Update D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME to a newer version that addresses this issue.
Exploit
Correção
Improper Authentication
Session Fixation
Insufficient Verification of Data Authenticity
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
D-Link Wireless N 300 Adsl2+ Modem Router Dsl-124 Me