Executive brief
ManageEngine DDI Central is a DNS, DHCP, and IP address management platform used by organizations to manage critical network infrastructure. An authentication bypass flaw in the password-reset workflow allows attackers to take over administrator accounts without valid credentials, leading to complete compromise of the network management system and potential unauthorized changes to DNS and DHCP configurations.
Technical details
An authentication bypass exists in DDI Central's password-reset verification workflow that fails to properly validate reset requests, allowing an attacker to reset any user's password and gain account access without possessing the original credentials. The vulnerability is exploitable remotely and does not require prior authentication or user interaction. An attacker can leverage a compromised administrative account to modify DNS zones, DHCP pools, and network configurations across managed infrastructure. The issue was fixed in Build 6201.
Affected products
- ManageEngine DDI Central before Build 6201
Timeline
- 2026-08-11: disclosed