← Vulnerability feed

Vulnerability record · CVE-2017-3191 · published 16 December 2017

CVE-2017-3191: D-Link DIR-130 and DIR-330 remote login authentication bypass

D Link · Dir 130 Firmware

D-Link DIR-130 firmware 1.23 and DIR-330 firmware 1.12 allow authentication bypass of the remote management login page. A remote attacker who can reach that page can craft a POST request to access administrator-only pages such as tools_admin.asp without credentials. This exposes full router administration to anyone who can reach the remote management interface.

9.8 CVSS 3.0 Critical EPSS 63% · top 0.8% CWE-294 · Authentication bypass by capture-replayCWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 5.0
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, and a very high EPSS percentile, make this a high-impact, remotely reachable flaw.

What it is

D-Link DIR-130 firmware 1.23 and DIR-330 firmware 1.12 allow authentication bypass of the remote management login page. A remote attacker who can reach that page can craft a POST request to access administrator-only pages such as tools_admin.asp without credentials. This exposes full router administration to anyone who can reach the remote management interface.

Impact

An unauthenticated attacker gains access to administrator-only pages, effectively full administrative control of the affected router. That enables configuration changes, credential exposure and use of the device as a pivot into the network.

Attack surface

Reachable over the network via the remote management login page (AV:N, PR:N, UI:N). No authentication or user interaction is required; the attacker only needs network access to the exposed management interface.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.62527, 99.15th percentile), and references are advisory and press coverage only, with no public exploit tag in the record.

What to do

  • Apply the vendor firmware fix for DIR-130 and DIR-330 if one is available; the record does not state a fixed version, so confirm with D-Link.
  • If no fix exists, replace the affected devices or take them out of service.
  • Disable remote management and restrict the admin interface to trusted internal networks only.
  • Place the management interface behind a firewall or VPN so it is not reachable from untrusted networks.
  • Change default administrative credentials and review router configuration for unauthorized changes.

Detection

  • Monitor router and firewall logs for POST requests to administrator pages such as tools_admin.asp from unauthenticated or unexpected sources.
  • Alert on access to the remote management login page from external or untrusted IP addresses.
  • Audit router configuration changes and administrative logins for activity that does not match a legitimate session.
  • Watch for anomalous outbound traffic or DNS behavior from affected routers that could indicate compromise.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3191 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2017-3191), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.