PT-2026-43097 · D Link · Dir601

Published

2026-05-23

·

Updated

2026-05-23

·

CVE-2018-25358

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions D-Link DIR601 version 2.02NA
Description A credential disclosure issue allows unauthenticated attackers to retrieve sensitive configuration data. By manipulating the table name parameter in POST requests sent to the '/my cgi.cgi' endpoint, attackers can extract administrative credentials and wireless network keys in clear text. Examples of values for the table name parameter include admin user, wireless settings, and wireless security.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25358

Affected Products

Dir601