CVE-2024-5296

D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TokenUtils class. The issue results from a hard-coded cryptographic key. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-21991.
Configurations

No configuration.

History

23 May 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-23 22:15

Updated : 2024-05-24 01:15


NVD link : CVE-2024-5296

Mitre link : CVE-2024-5296

CVE.ORG link : CVE-2024-5296


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key