CVE-2023-32169 is a critical authentication bypass vulnerability affecting D-Link D-View 8, stemming from the use of a hard-coded cryptographic key in the TokenUtils class. This flaw allows remote, unauthenticated attackers to completely bypass authentication, leading to full compromise of the system with a CVSS score of 9.8. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community attention and media coverage, indicating a high potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.1.27CPE matchmatch criteria | cpe:2.3:a:dlink:d-view_8:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.