VendorsD-Linkdir-600m_firmwareall versions
Vulnerabilities

D-Link DIR-600M Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2019-13101
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
Published 2019-08-08 · Modified
9.81 PoCEPSS 0.671
CVE-2019-7736
D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.
Published 2019-02-11 · Modified
9.8EPSS 0.027
CVE-2017-9100
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.
Published 2017-05-21 · Modified
8.8EPSS 0.855
CVE-2024-1786
D-Link DIR-600M C1 Telnet Service buffer overflow
Published 2024-02-23 · Analyzed
7.8EPSS 0.027
CVE-2020-13960
D-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows remote attackers to provide valid DNS responses (and also offer Internet services such as HTTP) for names that otherwise would have had an NXDOMAIN error, by registering a subdomain of the domain.name domain name.
Published 2020-06-08 · Modified
7.5EPSS 0.012
CVE-2018-16605
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
Published 2018-09-12 · Modified
5.4EPSS 0.009