← Vulnerability feed

Vulnerability record · CVE-2017-9100 · published 21 May 2017

CVE-2017-9100: D-Link DIR-600M login.cgi authentication bypass via blank password

Dlink · Dir 600m Firmware

The login.cgi handler on D-Link DIR-600M devices running firmware 3.04 fails to properly validate the admin password field, allowing authentication to be bypassed by submitting more than 20 blank spaces. This grants an unauthenticated attacker full administrative control of the router, which is a high-impact flaw for a network edge device.

8.8 CVSS 3.1 High EPSS 85% · top 0.3% CWE-287 · Improper authentication
8.8CVSS 3.1 base score, v2 8.3
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated admin bypass on a network edge device with public exploit code and very high EPSS, though exploitation requires adjacent network access and the CVE is not in KEV.

What it is

The login.cgi handler on D-Link DIR-600M devices running firmware 3.04 fails to properly validate the admin password field, allowing authentication to be bypassed by submitting more than 20 blank spaces. This grants an unauthenticated attacker full administrative control of the router, which is a high-impact flaw for a network edge device.

Impact

An attacker gains full administrative access to the router, enabling configuration changes, credential theft, traffic redirection, and use of the device as a pivot into the internal network.

Attack surface

The flaw is reachable over the adjacent network via the device's web management interface (login.cgi); no authentication is required and no user interaction is needed, per the CVSS vector AV:A/AC:L/PR:N/UI:N.

Exploitation

Public exploit code and proof-of-concept write-ups are referenced (Exploit-DB 42039, vendor blog, YouTube), and EPSS is very high at 0.997 percentile, though the CVE is not listed in CISA KEV.

What to do

  • Apply the latest D-Link firmware for DIR-600M if a fixed release exists; if the device is end-of-life, replace it.
  • Restrict access to the router's web management interface to trusted management networks only.
  • Disable remote administration and WAN-side access to login.cgi.
  • Change default admin credentials and monitor for unauthorized configuration changes.
  • Segment or retire the device if it cannot be patched.

Detection

  • Monitor router and web logs for login.cgi POST requests containing long runs of whitespace in the password parameter.
  • Alert on successful admin logins from unexpected source IPs or outside management hours.
  • Audit router configuration changes and new admin accounts for unauthorized modifications.
  • Watch for outbound connections from the router to known malicious or unusual destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://touhidshaikh.com/blog/poc/d-link-dir600-auth-bypass/ ExploitThird Party Advisory
https://www.exploit-db.com/exploits/42039/ ExploitThird Party AdvisoryVDB Entry
https://www.youtube.com/watch?v=waIJKWCpyNQ ExploitThird Party Advisory
http://touhidshaikh.com/blog/poc/d-link-dir600-auth-bypass/ ExploitThird Party Advisory
https://www.exploit-db.com/exploits/42039/ ExploitThird Party AdvisoryVDB Entry
https://www.youtube.com/watch?v=waIJKWCpyNQ ExploitThird Party Advisory

Track CVE-2017-9100 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-13101D-Link DIR-600M wan.htm missing authentication exposes and alters WAN settingsThe D-Link DIR-600M router firmware (versions 3.02, 3.03, 3.04, 3.06) allows the wan.htm page to be accessed directly without authentication. This mi…EPSS 67%analysed9.8CVE-2019-7736Dlink dir-600m firmware vulnerabilityD-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may overlap CVE-2019-13101.EPSS 2.7%7.5CVE-2024-1786Dlink dir-600m firmware classic buffer overflow vulnerability** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue …EPSS 2.7%7.5CVE-2020-13960Dlink dsl-2730u firmware vulnerabilityD-Link DSL 2730-U IN_1.10 and IN_1.11 and DIR-600M 3.04 devices have the domain.name string in the DNS resolver search path by default, which allows …EPSS 1.2%5.4CVE-2018-16605Dlink dir-600m firmware cross-site scripting vulnerabilityD-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.EPSS 0.90%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2017-9100), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.