CVE-2019-17505: D-Link Dap-1320 a2 Firmware

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink_info.xml. An attacker can remotely obtain a user's Wi-Fi SSID and password, which could be used to connect to Wi-Fi or perform a dictionary attack.

Affected products

  • D-Link Dap-1320 a2 Firmware: version 1.21 only

Published 2019-10-11. Last modified 2026-06-17.