CVE-2018-12710: D-Link Dir-601 Firmware

High severity, CVSS 8.0. EPSS: 76.5% chance of exploitation in the next 30 days.

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.

Affected products

  • D-Link Dir-601 Firmware: version 2.02na only

Published 2018-08-29. Last modified 2026-06-17.