D-Link DIR-605L
cpe:2.3:h:d-link:dir-605l:*:*:*:*:*:*:*, +2 more
- 2.02
- 3.02
A vulnerability exists in the D-Link DIR-605L and DIR-618 routers, specifically in versions 2.02 and 3.02. The issue arises from improper access controls in the web management interface, allowing unauthorized users to manipulate password settings. Exploitation requires sending an unauthenticated HTTP POST request to the '/goform/formSetPassword' endpoint.
Exploitation of this vulnerability allows for unauthorized password changes, potentially leading to unauthorized access or control over the device.
To reproduce this vulnerability, send an unauthenticated HTTP POST request to the '/goform/formSetPassword' endpoint. Include the new password in the request. The vulnerability can be exploited from within the local network.
It is recommended to implement proper firewall rules to block unauthorized access to the router's management interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.