Vulnerability record · CVE-2023-32169 · published 3 May 2024
CVE-2023-32169: D-Link D-View hard-coded key allows authentication bypass
Dlink · D View 8
D-Link D-View contains a hard-coded cryptographic key in the TokenUtils class, which lets an attacker forge authentication tokens and bypass login entirely. Because the key is static and shipped in the product, any remote attacker who knows it can authenticate as a legitimate user without credentials.
Description
D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of D-Link D-View. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TokenUtils class. The issue results from a hard-coded cryptographic key. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-19659.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a 99th percentile EPSS score, makes this an urgent exposure despite no KEV listing.
What it is
D-Link D-View contains a hard-coded cryptographic key in the TokenUtils class, which lets an attacker forge authentication tokens and bypass login entirely. Because the key is static and shipped in the product, any remote attacker who knows it can authenticate as a legitimate user without credentials.
Impact
An attacker gains full authenticated access to the D-View management system, with high confidentiality, integrity and availability impact per the CVSS vector, potentially allowing control of managed network devices.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/PR:N/UI:N and the description stating authentication is not required. The flaw sits in the TokenUtils token handling path.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.56064 (99th percentile), indicating a high likelihood of attempted exploitation; references are vendor and ZDI advisories only, with no public exploit tag.
What to do
- Apply the D-Link vendor advisory SAP10332 fix for D-View 8 as the first action.
- If no patch is available for your build, isolate D-View management interfaces from untrusted networks and restrict access to a management VLAN.
- Rotate or replace any hard-coded token signing keys where the product permits configuration.
- Monitor D-Link advisories for updated firmware and re-check exposure after patching.
Detection
- Alert on authentication or token-validation events from D-View that originate from unexpected source IPs or outside normal admin hours.
- Baseline legitimate D-View admin sessions and flag new sessions that skip normal login flows or use anomalous tokens.
- Review D-View logs for successful authentications without a corresponding credential-based login event.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-714/ | Third Party Advisory |
| https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-23-714/ | Third Party Advisory |
Track CVE-2023-32169 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32169), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.