PT-2026-3842 · D Link · D-Link D-View 8

·

CVE-2026-23754

·

Publicado

2026-01-21

·

Atualizado

2026-01-21

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link D-View 8 versions 2.0.1.107 and below
Description D-Link D-View 8 versions 2.0.1.107 and below have an improper access control issue in backend API endpoints. An authenticated user can provide an arbitrary user id value to obtain sensitive credential data for other users, including super administrators. This credential material can be directly used for authentication, enabling full impersonation of the targeted account and complete administrative control over the D-View system. The vulnerable API endpoints allow unauthorized access to user credentials through manipulation of the user id parameter.
Recommendations Versions prior to 2.0.1.107 should be updated.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00987
CVE-2026-23754

Produtos afetados

D-Link D-View 8