Junglewise Threat Intelligence

CVE-2018-25358: D-Link DIR-601 credential disclosure in my_cgi.cgi

CVE-2018-25358 · Severity: high · CVSS 7.5 · Published 2026-05-23

Vendors: D-Link.

Executive brief

A vulnerability in the D-Link DIR-601 router allows unauthorized individuals to remotely access sensitive device information. An attacker can exploit this to steal administrative login credentials and Wi-Fi passwords without needing any prior access. This could lead to a complete takeover of the home or office network, allowing attackers to monitor traffic or change security settings.

Technical details

A credential disclosure vulnerability exists in the D-Link DIR-601 router (firmware version 2.02NA and potentially earlier) due to improper access controls in the /my_cgi.cgi component. By sending a specially crafted HTTP POST request with a manipulated 'table_name' parameter, an unauthenticated remote attacker can query internal configuration tables. Specifically, requesting tables such as 'admin_user', 'wireless_settings', and 'wireless_security' returns administrative credentials and WPA/WEP wireless keys in clear text. This allows for full administrative compromise of the device over the network without user interaction.

Affected products

  • D-Link DIR-601 2.02NA and earlier

Timeline

  • 2026-05-23: advisory: NVD and VulnCheck published the advisory details.

References