CVE-2017-9100: D-Link Dir-600m Firmware

High severity, CVSS 8.8. EPSS: 85.5% chance of exploitation in the next 30 days.

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.

Affected products

  • D-Link Dir-600m Firmware: version 3.04 only

Published 2017-05-21. Last modified 2026-06-17.