Executive brief
A vulnerability in the D-Link DIR-601 router allows unauthorized individuals to remotely access sensitive device information. An attacker can exploit this to steal administrative login credentials and Wi-Fi passwords without needing any prior access. This could lead to a complete takeover of the home or office network, allowing attackers to monitor traffic or change security settings.
Technical details
A credential disclosure vulnerability exists in the D-Link DIR-601 router (firmware version 2.02NA and potentially earlier) due to improper access controls in the /my_cgi.cgi component. By sending a specially crafted HTTP POST request with a manipulated 'table_name' parameter, an unauthenticated remote attacker can query internal configuration tables. Specifically, requesting tables such as 'admin_user', 'wireless_settings', and 'wireless_security' returns administrative credentials and WPA/WEP wireless keys in clear text. This allows for full administrative compromise of the device over the network without user interaction.
Affected products
- D-Link DIR-601 2.02NA and earlier
Timeline
- 2026-05-23: advisory: NVD and VulnCheck published the advisory details.