← Vulnerability feed

Vulnerability record · CVE-2011-4723 · published 20 December 2011

CVE-2011-4723: D-Link DIR-300 router stores passwords in cleartext

Dlink · Dir 300 Firmware

The D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials directly, which matters because the device is end-of-life and no longer receives fixes.

5.7 CVSS 3.1 Medium CISA KEV since 8 Sep 2022 EPSS 3.1% · top 12.9% CWE-312 · Cleartext storage of sensitive data
5.7CVSS 3.1 base score, v2 6.8
3.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
16 Jun 2026Last modified by NVD

Description

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw exposes cleartext credentials and is in CISA KEV, but it requires adjacent network access and the affected product is end-of-life.

What it is

The D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials directly, which matters because the device is end-of-life and no longer receives fixes.

Impact

An attacker who obtains the stored data gains plaintext credentials, which can be reused against the router or other systems where the same password is used.

Attack surface

The CVSS vector is adjacent network with low privileges and no user interaction, so the attacker needs a foothold on the same network segment and some level of access, not necessarily administrative rights. The description does not specify the exact retrieval path.

Exploitation

CVE-2011-4723 is listed in CISA KEV, indicating exploitation in the wild, while EPSS is low at roughly 3 percent for the next 30 days. No ransomware campaign use is documented.

What to do

  • Replace or disconnect the DIR-300, which CISA notes is end-of-life and should not remain in use.
  • If the device must stay temporarily, isolate it on a separate network segment with no access to sensitive systems.
  • Change any password that was configured on the device and any reused elsewhere.
  • Restrict adjacent-network access to the device to trusted administrators only.

Detection

  • Monitor network traffic to and from DIR-300 management interfaces for unexpected access from non-admin hosts.
  • Audit router configuration backups and storage for cleartext credential exposure.
  • Alert on authentication attempts using credentials that were previously stored on the device.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2011-4723 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 29 September 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4723 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-10069Dlink dir-600 firmware os command injection vulnerabilityThe web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an unauthenticated OS command in…EPSS 17%9.8CVE-2024-41616Dlink dir-300 firmware hard-coded credentials vulnerabilityD-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.EPSS 0.76%9.8CVE-2023-31814Dlink dir-300 firmware vulnerabilityD-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.EPSS 0.89%9.8CVE-2013-7471Dlink dir-300 firmware command injection vulnerabilityAn issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 r…EPSS 24%9.3CVE-2013-10048Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmware ≤ 2.13 and ≤ 2.14b01, res…EPSS 17%8.7CVE-2013-10050Dlink dir-300 firmware os command injection vulnerabilityAn OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 rev D v4.13) via the authentica…EPSS 14%5.3CVE-2024-0717Dlink dir-825acg1 firmware information exposure vulnerabilityA vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DI…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2011-4723), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.