CVE-2018-10641: High severity d-link dir-601 firmware vulnerability
Published May 4, 2018
·Updated
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
Affected Software
2 affected components
Dlink Dir-601 Firmware=1.02na
Dlink Dir-600l=a1
Event History
May 4, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10641?
CVE-2018-10641 is considered a medium severity vulnerability due to its potential impact on user authentication.
2
How do I fix CVE-2018-10641?
To fix CVE-2018-10641, update the D-Link DIR-601 firmware to the latest version that addresses this vulnerability.
3
What devices are affected by CVE-2018-10641?
CVE-2018-10641 specifically affects D-Link DIR-601 A1 devices running firmware version 1.02NA.
4
What does CVE-2018-10641 exploit?
CVE-2018-10641 exploits a flaw that allows password changes without requiring the old password, which is conducted in cleartext.
5
Is there a workaround for CVE-2018-10641?
A temporary workaround for CVE-2018-10641 is to disable remote management features, but updating the firmware is the recommended solution.