Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-9100

Description

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.

POC

Reference

- http://touhidshaikh.com/blog/poc/d-link-dir600-auth-bypass/

- https://www.exploit-db.com/exploits/42039/

- https://www.youtube.com/watch?v=waIJKWCpyNQ

Github

No PoCs found on GitHub currently.