CVE-2018-25358: D-Link DIR601 2.02NA Credential Disclosure via my_cgi.cgi
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the tablename parameter in POST requests. Attackers can send requests to /mycgi.cgi with tablename values like adminuser, wirelesssettings, and wirelesssecurity to extract administrative credentials and wireless network keys in clear text.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25358?
CVE-2018-25358 has a high severity rating of 7.5.
How do I fix CVE-2018-25358?
To mitigate CVE-2018-25358, update to the latest firmware provided by D-Link for the DIR601 model.
What type of vulnerability is CVE-2018-25358?
CVE-2018-25358 is a credential disclosure vulnerability that allows unauthorized access to sensitive configuration data.
What can attackers do with CVE-2018-25358?
Attackers can exploit CVE-2018-25358 to retrieve sensitive configuration details by manipulating POST requests.
Is authentication required to exploit CVE-2018-25358?
No, CVE-2018-25358 can be exploited without any authentication.