S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-5074 Scanner

Detects 'Hard-Coded JWT Token' vulnerability in D-Link D-View 8 affects v. 2.0.1.28.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-5074
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
D-View 8by D-Link
2.0.1.28
d-view_8by dlink
2.0.1.28
Updated Sep 10, 2026View on NVD →
Detail

D-Link D-View 8 is a network management software used to manage and monitor multiple devices in a network. It allows administrators to view device status, configure settings, and troubleshoot issues in real-time. It is commonly used in enterprise networks to ensure smooth operations.

Recently, a vulnerability identified as CVE-2023-5074 has been detected in D-Link D-View 8 v2.0.1.28. This vulnerability is related to the use of a static key for protecting JSON Web Token (JWT) tokens that are used for user authentication. Since the same key is used for all users, an attacker can easily obtain the key and use it to modify the token and gain access to the network.

The exploitation of CVE-2023-5074 can lead to serious consequences as it allows unauthorized access to the network by attackers. The attackers can modify device configurations, steal sensitive data, and launch other attacks on the network. This can lead to financial loss, reputational damage, and even legal action against the organization.

s4e.io is a platform that provides comprehensive information and tools to detect vulnerabilities in digital assets. By subscribing to its pro features, users can easily and quickly identify vulnerabilities in their network and take necessary actions to mitigate them. With its user-friendly interface and up-to-date database of vulnerabilities, s4e.io is a reliable solution for network administrators to ensure the security of their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, administrators can take the following precautions:

  • Upgrade the D-View 8 software to the latest version, where the vulnerability has been patched.
  • Disable the D-View 8 web interface if it is not required.
  • Restrict network access to D-View 8 to trusted IP addresses only.
  • Monitor network activity for any suspicious behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-5074 scanner - Hard-Coded JWT Token vulnerability in D-Link D-View 8 | S4E