Dlink Dir-600M Firmware vulnerabilities

5 known vulnerabilities affecting dlink/dir-600m_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH3

Vulnerabilities

Page 1 of 1
CVE-2024-1786HIGHCVSS 7.5v3.082024-02-23
CVE-2024-1786 [HIGH] CWE-120 CVE-2024-1786: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation of the argument username leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the
nvd
CVE-2020-13960HIGHCVSS 7.5v3.042020-06-08
CVE-2020-13960 [HIGH] CVE-2020-13960: D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the D D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows remote attackers to provide valid DNS responses (and also offer Internet services such as HTTP) for names that otherwise would have had an NXDOMAIN error, by registering a subdomain of the domain.name domain name
nvd
CVE-2019-13101CRITICALCVSS 9.8PoCv3.02v3.03+2 more2019-08-08
CVE-2019-13101 [CRITICAL] CWE-306 CVE-2019-13101: An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be access An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
nvd
CVE-2019-7736CRITICALCVSS 9.8v3.042019-02-11
CVE-2019-7736 [CRITICAL] CVE-2019-7736: D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.
nvd
CVE-2017-9100HIGHCVSS 8.8v3.042017-05-21
CVE-2017-9100 [HIGH] CWE-287 CVE-2017-9100: login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentica login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.
nvd