Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to login to the device as an authenticated user without the access privilege via unspecified vectors.
https://www.dlink-jp.com/support/release/jvnvu92898656_dap-1880ac.html