D-Link DIR-605L and DIR-618 Improper Access Control Vulnerability

Vulnerability

A vulnerability allowing improper access control has been identified in the D-Link DIR-605L and DIR-618 routers, specifically in versions 2.02 and 3.02. This issue arises in the web management interface, where the file '/goform/formVirtualServ' is processed. The vulnerability allows unauthorized users to manipulate virtual service settings by sending specially crafted HTTP POST requests. Exploitation of this vulnerability requires no authentication and can be performed from within the local network.

Impact

Exploitation of this vulnerability allows unauthorized users to change the virtual service settings on the affected router, potentially leading to misconfigurations or unauthorized access to network services.

Reproduction

To reproduce this vulnerability, send an unauthenticated HTTP POST request to the '/goform/formVirtualServ' endpoint. Include the 'formVirtualServ' header to specify the virtual service settings to be modified. This can be done using tools like curl or Postman, or through a custom script that automates the process.

Remediation

It is recommended to use a firewall to block unauthorized access to the router's management interface.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.