Vulnerability record · CVE-2011-4723 · published 20 December 2011
CVE-2011-4723: D-Link DIR-300 router stores passwords in cleartext
Dlink · Dir 300 Firmware
The D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials directly, which matters because the device is end-of-life and no longer receives fixes.
Description
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw exposes cleartext credentials and is in CISA KEV, but it requires adjacent network access and the affected product is end-of-life.
What it is
The D-Link DIR-300 router stores passwords in cleartext rather than in a protected form. Anyone who can reach the stored data can read credentials directly, which matters because the device is end-of-life and no longer receives fixes.
Impact
An attacker who obtains the stored data gains plaintext credentials, which can be reused against the router or other systems where the same password is used.
Attack surface
The CVSS vector is adjacent network with low privileges and no user interaction, so the attacker needs a foothold on the same network segment and some level of access, not necessarily administrative rights. The description does not specify the exact retrieval path.
Exploitation
CVE-2011-4723 is listed in CISA KEV, indicating exploitation in the wild, while EPSS is low at roughly 3 percent for the next 30 days. No ransomware campaign use is documented.
What to do
- Replace or disconnect the DIR-300, which CISA notes is end-of-life and should not remain in use.
- If the device must stay temporarily, isolate it on a separate network segment with no access to sensitive systems.
- Change any password that was configured on the device and any reused elsewhere.
- Restrict adjacent-network access to the device to trusted administrators only.
Detection
- Monitor network traffic to and from DIR-300 management interfaces for unexpected access from non-admin hosts.
- Audit router configuration backups and storage for cleartext credential exposure.
- Alert on authentication attempts using credentials that were previously stored on the device.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2011-4723 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability". Required action: The impacted product is end-of-life and should be disconnected if still in use. Federal deadline 29 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://en.securitylab.ru/lab/PT-2011-30 | Broken Link |
| http://en.securitylab.ru/lab/PT-2011-30 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-4723 | US Government Resource |
Track CVE-2011-4723 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4723), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.