Vulnerability record · CVE-2017-3191 · published 16 December 2017
CVE-2017-3191: D-Link DIR-130 and DIR-330 remote login authentication bypass
D Link · Dir 130 Firmware
D-Link DIR-130 firmware 1.23 and DIR-330 firmware 1.12 allow authentication bypass of the remote management login page. A remote attacker who can reach that page can craft a POST request to access administrator-only pages such as tools_admin.asp without credentials. This exposes full router administration to anyone who can reach the remote management interface.
Description
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, and a very high EPSS percentile, make this a high-impact, remotely reachable flaw.
What it is
D-Link DIR-130 firmware 1.23 and DIR-330 firmware 1.12 allow authentication bypass of the remote management login page. A remote attacker who can reach that page can craft a POST request to access administrator-only pages such as tools_admin.asp without credentials. This exposes full router administration to anyone who can reach the remote management interface.
Impact
An unauthenticated attacker gains access to administrator-only pages, effectively full administrative control of the affected router. That enables configuration changes, credential exposure and use of the device as a pivot into the network.
Attack surface
Reachable over the network via the remote management login page (AV:N, PR:N, UI:N). No authentication or user interaction is required; the attacker only needs network access to the exposed management interface.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.62527, 99.15th percentile), and references are advisory and press coverage only, with no public exploit tag in the record.
What to do
- Apply the vendor firmware fix for DIR-130 and DIR-330 if one is available; the record does not state a fixed version, so confirm with D-Link.
- If no fix exists, replace the affected devices or take them out of service.
- Disable remote management and restrict the admin interface to trusted internal networks only.
- Place the management interface behind a firewall or VPN so it is not reachable from untrusted networks.
- Change default administrative credentials and review router configuration for unauthorized changes.
Detection
- Monitor router and firewall logs for POST requests to administrator pages such as tools_admin.asp from unauthenticated or unexpected sources.
- Alert on access to the remote management login page from external or untrusted IP addresses.
- Audit router configuration changes and administrative logins for activity that does not match a legitimate session.
- Watch for anomalous outbound traffic or DNS behavior from affected routers that could indicate compromise.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/123293 | VDB Entry |
| https://www.kb.cert.org/vuls/id/553503 | Issue TrackingThird Party AdvisoryUS Government Resource |
| https://www.scmagazine.com/d-link-dir-130-and-dir-330-routers-vulnerable/article/644553/ | Press/Media Coverage |
| https://www.wilderssecurity.com/threads/d-link-dir-130-and-dir-330-are-vulnerable-to-authentication-bypass-and-do-not-pr | Issue TrackingThird Party Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/123293 | VDB Entry |
| https://www.kb.cert.org/vuls/id/553503 | Issue TrackingThird Party AdvisoryUS Government Resource |
| https://www.scmagazine.com/d-link-dir-130-and-dir-330-routers-vulnerable/article/644553/ | Press/Media Coverage |
| https://www.wilderssecurity.com/threads/d-link-dir-130-and-dir-330-are-vulnerable-to-authentication-bypass-and-do-not-pr | Issue TrackingThird Party Advisory |
Track CVE-2017-3191 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-3191), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.