First published: Wed Jun 20 2018(Updated: )
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D-Link DIR-620S | =1.0.3 | |
D-Link DIR-620S | =1.0.37 | |
D-Link DIR-620S | =1.3.1 | |
D-Link DIR-620S | =1.3.3 | |
D-Link DIR-620S | =1.3.7 | |
D-Link DIR-620S | =1.4.0 | |
D-Link DIR-620S | =2.0.22 | |
D-Link DIR-620 Firmware | =1.0.3 | |
D-Link DIR-620 Firmware | =1.0.37 | |
D-Link DIR-620 Firmware | =1.3.1 | |
D-Link DIR-620 Firmware | =1.3.3 | |
D-Link DIR-620 Firmware | =1.3.7 | |
D-Link DIR-620 Firmware | =1.4.0 | |
D-Link DIR-620 Firmware | =2.0.22 | |
dlink DIR-620 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6213 is classified as a high severity vulnerability due to the presence of a hardcoded password.
To fix CVE-2018-6213, update the D-Link DIR-620 device to a firmware version that does not include the hardcoded password.
The affected firmware versions for CVE-2018-6213 are 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22.
A hardcoded password allows unauthorized access to the admin account, compromising the device's security.
Yes, CVE-2018-6213 can be exploited by attackers who can use the hardcoded password to gain administrative control over the affected devices.