Descripción
D-Link DAP-1325 firmware version 1.01 contains a broken access control vulnerability that allows unauthenticated attackers to download device configuration settings without authentication. Attackers can exploit the /cgi-bin/ExportSettings.sh endpoint retrieve sensitive information by directly accessing export script.
https://www.dlink.com/hr/hr/products/dap-1325-n300-wifi-range-extender
https://www.exploit-db.com/exploits/51556
https://www.vulncheck.com/advisories/d-link-dap-hardware-a-unauthenticated-configuration-download