vendor:
DIR-601
by:
Kevin Randall
8.0
CVSS
HIGH
Password Disclosure
200
CWE
Product Name: DIR-601
Affected Version From: Firmware: 2.02NA Hardware Version B1
Affected Version To: Firmware: 2.02NA Hardware Version B1
Patch Exists: YES
Related CWE: CVE-2018-5708
CPE: h:dlink:dir-601
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 + Mozilla Firefox
2017
DLink DIR-601 Unauthenticated Admin password disclosure
Having local access to the network but being unauthenticated to the administrator panel, a user can disclose the built in Admin username/password to access the admin panel. By accessing the default gateway/router login page, a user can login with Username Admin and put any random password. Then, by clearing the password that was set, a POST request will come back with the Admin username/password.
Mitigation:
Ensure that the router is updated to the latest firmware version and that the default username and password are changed.