← Vulnerability feed

Vulnerability record · CVE-2023-46033 · published 19 October 2023

CVE-2023-46033: Dlink dsl-2730u firmware improper access control vulnerability

Dlink · Dsl 2730u Firmware

D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.

6.8 CVSS 3.1 Medium EPSS 0.33% · top 76.8% CWE-284 · Improper access control
6.8CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

D-Link (Non-US) DSL-2750U N300 ADSL2+ and (Non-US) DSL-2730U N150 ADSL2+ are vulnerable to Incorrect Access Control. The UART/Serial interface on the PCB, provides log output and a root terminal without proper access control.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46033 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-1010155Dlink dsl-2750u firmware vulnerabilityD-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. The component is: login. NOTE:…EPSS 8.6%8.8CVE-2017-6411Dlink dsl-2730u firmware cross-site request forgery vulnerabilityCross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any p…EPSS 3.0%7.8CVE-2021-3708Dlink dsl-2750u firmware os command injection vulnerabilityD-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local netwo…EPSS 25%7.8CVE-2020-13150Dlink dsl-2750u firmware missing authentication for critical function vulnerabilityD-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filterin…EPSS 0.28%7.5CVE-2020-13960Dlink dsl-2730u firmware vulnerabilityD-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows …EPSS 1.2%5.5CVE-2021-3707Dlink dsl-2750u firmware vulnerabilityD-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to unauthorized configuration modification. An unauthenticated attacker…EPSS 1.5%5.3CVE-2024-0717Dlink dir-825acg1 firmware information exposure vulnerabilityA vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DI…EPSS 18%5.1CVE-2024-9792Dlink dsl-2750u firmware cross-site scripting vulnerabilityA vulnerability classified as problematic has been found in D-Link DSL-2750U R5B017. This affects an unknown part of the component Port Forwarding Pa…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2023-46033), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.