CVE-2019-13101
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 67.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 67.09% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- dlink/dir-600m firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/153994/D-Link-DIR-600M-Wireless-N-150-Home-Router-Access-Bypass.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Aug/5Mailing List, Third Party Advisory
- https://github.com/d0x0/D-Link-DIR-600M/blob/master/CVE-2019-13101Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/17Mailing List, Third Party Advisory
- https://us.dlink.com/en/security-advisoryVendor Advisory
- https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfThird Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/153994/D-Link-DIR-600M-Wireless-N-150-Home-Router-Access-Bypass.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Aug/5Mailing List, Third Party Advisory
- https://github.com/d0x0/D-Link-DIR-600M/blob/master/CVE-2019-13101Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/17Mailing List, Third Party Advisory
- https://us.dlink.com/en/security-advisoryVendor Advisory
- https://www.ftc.gov/system/files/documents/cases/dlink_proposed_order_and_judgment_7-2-19.pdfThird Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.