Vulnerability Description
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware image can extract these credentials using static analysis tools such as strings or xxd, potentially leading to unauthorized access to device functions or user accounts. This vulnerability exists due to insecure storage of sensitive information in the firmware binary.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dph-400Se Firmware | 1.01 |
| Dlink | Dph-400Se | - |
| Dlink | Dph-400S Firmware | 1.01 |
| Dlink | Dph-400S | - |
Related Weaknesses (CWE)
References
- https://cybermaya.in/posts/Post-37/ExploitThird Party Advisory
- https://www.dlink.com/en/security-bulletin/Vendor Advisory
FAQ
What is CVE-2025-45784?
CVE-2025-45784 is a vulnerability with a CVSS score of 9.8 (CRITICAL). D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including PROVIS_USER_PASSWORD, which may expose sensitive user credentials. An attacker with access to the firmware imag...
How severe is CVE-2025-45784?
CVE-2025-45784 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-45784?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dph-400Se Firmware, Dlink Dph-400Se, Dlink Dph-400S Firmware, Dlink Dph-400S.