Vulnerabilities (CVE)

Filtered by vendor D-link Subscribe
Filtered by product Dir-601 Firmware
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10641 1 D-link 2 Dir-600l, Dir-601 Firmware 2019-10-03 6.8 MEDIUM 8.1 HIGH
D-Link DIR-601 A1 1.02NA devices do not require the old password for a password change, which occurs in cleartext.
CVE-2018-12710 1 D-link 2 Dir-601, Dir-601 Firmware 2019-10-03 2.7 LOW 8.0 HIGH
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.