CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2019-13101

CVSS 9.8v3.1pub. 2019-08-08upd. 2024-11-21

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Dlink Dir 600m

    HW
    Dlink
    all versions
  • Dlink Dir 600m Firmware

    OS
    Dlink
    3.023.033.043.06
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2019-7736CRITICAL9.8PL ✓same product

D-Link DIR-600M: pominięcie uwierzytelnienia via bezpośrednie żądanie do wan.htm

CVE-2024-1786HIGH7.5same product

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DI...

CVE-2020-13960HIGH7.5same product

D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolve...

CVE-2017-9100HIGH8.8same product

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by en...

CVE-2017-5874HIGH8.8same product

CSRF exists on D-Link DIR-600M Rev. Cx devices before v3.05ENB01_beta_20170306. This can be used to bypass aut...