CVE-2018-5708

HIGH

D-Link DIR-601 B1 2.02NA - Info Disclosure

Title source: llm

Description

An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the response (specifically, the configuration file restore_default), which is displayed in XML.

Exploits (2)

github NO CODE
by KevinRandall1337 · poc
https://github.com/KevinRandall1337/CVE-Security-Research/tree/master/CVE-2018-5708
exploitdb WORKING POC
by Kevin Randall · textwebappshardware
https://www.exploit-db.com/exploits/44388

Scores

CVSS v3 8.0
EPSS 0.0559
EPSS Percentile 90.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (1)

dlink/dir-601_firmware

Timeline

Published Mar 30, 2018
Tracked Since Feb 18, 2026