Junglewise Threat Intelligence

CVE-2011-4723: D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability

CVE-2011-4723 · Severity: critical · CVSS 6.8 · Exploited in the wild · Published 2022-09-08

Vendors: D-Link.

Executive brief

The D-Link DIR-300 router stores passwords in cleartext format. This vulnerability allows authenticated or context-dependent attackers to obtain sensitive administrative information via unspecified vectors.

Affected products

  • D-Link DIR-300 firmware -
  • D-Link DIR-300 hardware -

Timeline

  • 2011-12-20: disclosed: Initial NVD publication date
  • 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-29: other: CISA due date for remediation (disconnection of EOL device)