CVE-2013-6026: Critical severity d-link di-524up vulnerability

Published Oct 19, 2013
·
Updated

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlsetroodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.

Affected Software

13 affected components
Dlink Di-524up
Dlink Di-604\+
Dlink Di-604s
Dlink Di-604up
Dlink Di-624s
Dlink Dir-100
Dlink Dir-120
Dlink Tm-g5240
Alphanetworks Vdsl Asl-55052
Alphanetworks Vdsl Asl-56552
PLANEX BRL-04CW
PLANEX BRL-04R
PLANEX BRL-04UR

Event History

Oct 19, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2013-6026?

The severity of CVE-2013-6026 is critical, as it allows unauthorized remote access to router configurations.

2

How do I fix CVE-2013-6026?

To fix CVE-2013-6026, update your router firmware to the latest version recommended by the manufacturer.

3

Which devices are affected by CVE-2013-6026?

CVE-2013-6026 affects various D-Link, Planex, and Alpha Networks routers, including models DIR-100 and DI-524UP.

4

What exploitation methods are used for CVE-2013-6026?

CVE-2013-6026 can be exploited by bypassing authentication through specific crafted URLs targeting the router's web interface.

5

What potential impacts does CVE-2013-6026 have?

The potential impacts of CVE-2013-6026 include unauthorized changes to router settings, which can lead to data breaches or loss of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203