CVE-2017-9100

HIGH

D-Link DIR-600M <3.04 - Auth Bypass

Title source: llm
STIX 2.1

Description

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.

Exploits (1)

exploitdb WORKING POC
by Touhid M.Shaikh · textwebappshardware
https://www.exploit-db.com/exploits/42039

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
http://touhidshaikh.com/blog/poc/d-link-dir600-auth-bypass/
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/42039/
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=waIJKWCpyNQ

Scores

CVSS v3 8.8
EPSS 0.0577
EPSS Percentile 90.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (1)
dlink/dir-600m_firmware 3.04
Published May 21, 2017
Tracked Since Feb 18, 2026