Executive brief
A vulnerability in the D-Link DSL-124 modem router allows unauthorized individuals on the same network to take over an administrator's session. The device incorrectly identifies logged-in users based only on their IP address rather than secure digital keys. An attacker can exploit this to gain full control over the router's settings, potentially leading to network disruption or unauthorized configuration changes.
Technical details
A session management vulnerability exists in the web management interface of the D-Link DSL-124 router (firmware ME_1.00). The application fails to implement session cookies or tokens, instead relying exclusively on the client's source IP address to identify authenticated sessions. An attacker on the local (adjacent) network can spoof the IP address of a currently authenticated user to bypass authentication. This allows the attacker to perform arbitrary administrative actions without providing valid credentials. As of the advisory date, no specific patch for version ME_1.00 is detailed beyond general security bulletins.
Affected products
- D-Link DSL-124 ME_1.00
Timeline
- 2026-02-25: disclosed
- 2026-02-26: advisory