CVE-2024-5296

D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TokenUtils class. The issue results from a hard-coded cryptographic key. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21991.
Configurations

No configuration.

History

21 Nov 2024, 09:47

Type Values Removed Values Added
References () https://www.zerodayinitiative.com/advisories/ZDI-24-447/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-447/ -

24 May 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-23 22:15

Updated : 2024-11-21 09:47


NVD link : CVE-2024-5296

Mitre link : CVE-2024-5296

CVE.ORG link : CVE-2024-5296


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key