CVE-2023-5074 is a critical authentication bypass vulnerability affecting D-Link D-View 8 v2.0.1.28, stemming from the use of a static key to protect JWT tokens during user authentication. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability allows unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) remotely with low attack complexity. While not yet in CISA's KEV catalog, exploit intelligence shows available Nuclei templates and significant community discussion, suggesting a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.1.28CPE matchmatch criteria | cpe:2.3:a:dlink:d-view_8:2.0.1.28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Authentication Bypass in D-Link D-View 8
Sep 19, 2023Authentication Bypass in D-Link D-View 8
Sep 19, 2023Authentication Bypass in D-Link D-View 8
Sep 19, 2023Authentication Bypass in D-Link D-View 8
Sep 19, 2023