D-Link Dir-600L Firmware vulnerabilities
3 known vulnerabilities affecting d-link/dir-600l_firmware.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-42374P3HIGHCVSS 8.8vB12026-05-04
CVE-2026-42374 [HIGH] CWE-798 CVE-2026-42374: D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device
D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn61_dlwbr_dir600L" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login bi
nvd
CVE-2026-42375P3HIGHCVSS 8.8vA12026-05-04
CVE-2026-42375 [HIGH] CWE-798 CVE-2026-42375: D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device
D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static password "wrgn35_dlwbr_dir600l" read from /etc/alpha_config/image_sign. The custom telnetd binary accepts a -u user:password flag, and the custom login bi
nvd
CVE-2016-10405P3CRITICALCVSS 9.8≤ 1.162017-09-07
CVE-2016-10405 [CRITICAL] CWE-384 CVE-2016-10405: Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01
Session fixation vulnerability in D-Link DIR-600L routers (rev. Ax) with firmware before FW1.17.B01 allows remote attackers to hijack web sessions via unspecified vectors.
nvd