---
id: CVE-2023-53974
title: >-
  D-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via
  Unauthenticated Request
summary: >-
  D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability
  that allows unauthenticated attackers to retrieve router settings through a
  POST request. Attackers can send a specific POST request to the router's
  configurat…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-306
vendor: D-Link
product: DSL-124 Wireless N300 ADSL2+
affected:
  - dsl-124_wireless_n300_adsl2+ ME_1.00
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-12-22T21:58:21.363481Z'
exploitAvailable: true
published: '2025-12-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:43.975Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-53974'
references:
  - url: 'https://www.exploit-db.com/exploits/51129'
    label: ExploitDB-51129
  - url: 'https://www.dlink.com'
    label: D-Link Official Homepage
  - url: >-
      https://dlinkmea.com/index.php/product/details?det=dU1iNFc4cWRsdUpjWEpETFlSeFlZdz09
    label: D-Link MEA Product Details Page
  - url: >-
      https://www.vulncheck.com/advisories/d-link-dsl-me-backup-configuration-file-disclosure-via-unauthenticated-request
    label: >-
      VulnCheck Advisory: D-Link DSL-124 ME_1.00 Backup Configuration File
      Disclosure via Unauthenticated Request
tags:
  - cve.org
  - exploit-available
epss: 0.00527
epssPercentile: 0.42554
ingestedAt: '2026-10-01T15:48:17.871Z'
---

## Overview

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configuration endpoint to download a complete backup file containing sensitive network credentials and system configurations.

## Affected

- `dsl-124_wireless_n300_adsl2+ ME_1.00`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
