CVE-2023-32148 is an authentication bypass vulnerability affecting D-Link DIR-2640 routers, specifically within the web management interface. An attacker can exploit this flaw by sending a crafted XML element in a login request, allowing them to bypass authentication without valid credentials. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited by network-adjacent attackers with low complexity and results in high integrity impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.11b02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-2640_firmware:1.11b02:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.