CVE-2025-71057

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a session hijacking attack via spoofing the IP address of an authenticated user.
Configurations

No configuration.

History

26 Feb 2026, 20:31

Type Values Removed Values Added
CWE CWE-345
CWE-287
CWE-384
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2

26 Feb 2026, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 16:23

Updated : 2026-02-27 14:06


NVD link : CVE-2025-71057

Mitre link : CVE-2025-71057

CVE.ORG link : CVE-2025-71057


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication

CWE-345

Insufficient Verification of Data Authenticity

CWE-384

Session Fixation