peter bassill · operator
$ cve CVE-2019-13101 JSON

CVE-2019-13101 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 67.1% (pctl 99)

Patch early

A public exploit exists.

Description

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS67.09% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2019-08-08
Last modified2026-06-17

Affected (2)

VendorProduct
dlinkdir-600m
dlinkdir-600m firmware

Public exploits

SourceTitleDate
exploit-dbD-Link DIR-600M - Authentication Bypass (Metasploit)2019-08-14

References

→ the Explorer  ·  watch your stack  ·  NVD