An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDlink Dir 600m
HWDlinkall versionsDlink Dir 600m Firmware
OSDlink3.023.033.043.06
Related vulnerabilities
D-Link DIR-600M: pominięcie uwierzytelnienia via bezpośrednie żądanie do wan.htm
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DI...
D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolve...
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by en...
CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass aut...