CVE-2018-6213: Critical severity D-Link DIR-620 vulnerability
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6213?
CVE-2018-6213 is classified as a high severity vulnerability due to the presence of a hardcoded password.
How do I fix CVE-2018-6213?
To fix CVE-2018-6213, update the D-Link DIR-620 device to a firmware version that does not include the hardcoded password.
Which D-Link DIR-620 firmware versions are affected by CVE-2018-6213?
The affected firmware versions for CVE-2018-6213 are 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22.
Why is hardcoded password a security risk in CVE-2018-6213?
A hardcoded password allows unauthorized access to the admin account, compromising the device's security.
Is there a known exploit for CVE-2018-6213?
Yes, CVE-2018-6213 can be exploited by attackers who can use the hardcoded password to gain administrative control over the affected devices.