CVE-2011-4723: D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Disconnect any D-Link DIR-300 routers from all networks if still in use: unplug network cables, disable Wi‑Fi, and remove Internet connectivity to isolate the device from production environments.
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4723?
CVE-2011-4723 has a moderate severity level due to the exposure of cleartext passwords.
How do I fix CVE-2011-4723?
To fix CVE-2011-4723, you should update the D-Link DIR-300 router to the latest firmware version provided by the manufacturer.
What type of attacks can exploit CVE-2011-4723?
CVE-2011-4723 can be exploited by context-dependent attackers aiming to access sensitive information stored in cleartext.
What devices are affected by CVE-2011-4723?
CVE-2011-4723 specifically affects the D-Link DIR-300 router.
Is there a workaround for CVE-2011-4723?
A possible workaround for CVE-2011-4723 is to restrict access to the router's management interface and avoid storing sensitive information in cleartext.