There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can get the router's log file via log_get.php, which could be used to discover the intranet network structure.
- https://github.com/dahua966/Routers-vuls
- https://github.com/20142995/pocsuite
- https://github.com/ARPSyndicate/cvemon