Executive brief
D-Link DIR-605 routers contain an information disclosure vulnerability due to incorrect authorization. An attacker can obtain the device's username and password by sending a forged POST request to the /getcfg.php page.
Affected products
- D-Link DIR-605 B2 Firmware 2.01MT
- D-Link DIR-605L B2 Firmware 2.01MT
Timeline
- 2021-09-24: disclosed: NVD Published Date
- 2024-05-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-05-16: exploited: CISA confirmed exploitation in the wild