CVE-2017-9542
9.8
CRITICAL · CVSS 3.0 · EPSS 5.1% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 5.07% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-06-11 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| d-link | dir-615 firmware |
| dlink | dir-615 |
References
- http://www.securityfocus.com/bid/98992
- https://twitter.com/tiger_tigerboy/status/873458088321220609
- https://www.facebook.com/tigerBOY777/videos/1368513696568992/
- http://www.securityfocus.com/bid/98992
- https://twitter.com/tiger_tigerboy/status/873458088321220609
- https://www.facebook.com/tigerBOY777/videos/1368513696568992/
→ the Explorer · watch your stack · NVD