CVE-2013-7005: D-Link Dsr-1000

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 stores account passwords in cleartext, which allows local users to obtain sensitive information by reading the Users[#]["Password"] fields in /tmp/teamf1.cfg.ascii.

Affected products

  • D-Link Dsr-1000
  • D-Link Dsr-1000 Firmware: up to and including 1.08b51; version 1.01b50 only; version 1.02b11 only; version 1.02b25 only; version 1.03b12 only; version 1.03b23 only; …
  • D-Link Dsr-1000n
  • D-Link Dsr-1000n Firmware: up to and including 1.08b51; version 1.01b50 only; version 1.02b11 only; version 1.02b25 only; version 1.03b12 only; version 1.03b23 only; …
  • D-Link Dsr-150
  • D-Link Dsr-150 Firmware: up to and including 1.08b29; version 1.05b29 only; version 1.05b35 only; version 1.05b46 only; version 1.05b50 only
  • D-Link Dsr-150n
  • D-Link Dsr-150n Firmware: up to and including 1.05b48
  • D-Link Dsr-250
  • D-Link Dsr-250 Firmware: up to and including 1.08b39; version 1.01b46 only; version 1.01b56 only; version 1.05b20 only; version 1.05b53 only; version 1.08b31 only
  • D-Link Dsr-250n Firmware: up to and including 1.08b39; version 1.01b46 only; version 1.01b56 only; version 1.05b20 only; version 1.05b53 only; version 1.08b31 only
  • D-Link Dsr-500
  • D-Link Dsr-500 Firmware: up to and including 1.08b51; version 1.02b11 only; version 1.02b25 only; version 1.03b12 only; version 1.03b23 only; version 1.03b27 only; …
  • D-Link Dsr-500n
  • D-Link Dsr-500n Firmware: up to and including 1.08b51; version 1.02b11 only; version 1.02b25 only; version 1.03b12 only; version 1.03b23 only; version 1.03b27 only; …

Published 2013-12-19. Last modified 2026-06-17.