CVE-2017-9542: D-Link Dir-615 Firmware

Critical severity, CVSS 9.8. EPSS: 5.1% chance of exploitation in the next 30 days.

D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.

Affected products

  • D-Link Dir-615 Firmware: any version

Published 2017-06-11. Last modified 2026-06-17.