CVE-2018-12710
published 2018-08-29CVE-2018-12710: An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access…
PriorityP268high8CVSS 3.0
AVAACLPRLUINSUCHIHAH
EXPLOIT
EPSS
76.51%
99.5th percentile
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dlink | dir-601_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandrequest=load_settings&table_name=admin_user&table_name=user_user&table_name=graph_auth&table_name=remote_management&table_name=system&table_name=virtual_server&table_name=port_forwarding&table_name=application_rules&table_name=inbound_filter&table_name=fw_ver&table_name=hw_ver↗
- →Monitor for POST requests to /my_cgi.cgi with body parameter 'request=load_settings' combined with 'table_name=admin_user', which triggers the credential disclosure response containing admin passwords in plaintext XML. ↗
- →Detect HTTP responses from /my_cgi.cgi with Content-type: text/xml that contain credential fields in XML body — the admin password is returned in cleartext in the response. ↗
- →Flag POST requests to /my_cgi.cgi with 'request=login' and 'user_type=1' (User role login) originating from internal network hosts, as this is the initial step of the exploit chain. ↗
- →The server banner 'lighttpd/1.4.28' in HTTP responses can help fingerprint vulnerable D-Link DIR-601 2.02NA devices on the network. ↗
- ·The exploit requires the attacker to already be local to the network and possess a valid low-privilege 'User' account. Remote exploitation is not possible without LAN access. ↗
- ·The vulnerability is confirmed only on firmware version 2.02NA, hardware version B1 of the D-Link DIR-601. Other firmware versions are not confirmed affected. ↗
- ·The admin password is exposed in the XML response body in plaintext, meaning no decryption or cracking is required — interception of the response is sufficient for full credential disclosure. ↗
CVSS provenance
nvdv3.08.0HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
2018-08-29
Published