Vulnerability record · CVE-2017-9100 · published 21 May 2017
CVE-2017-9100: D-Link DIR-600M login.cgi authentication bypass via blank password
Dlink · Dir 600m Firmware
The login.cgi handler on D-Link DIR-600M devices running firmware 3.04 fails to properly validate the admin password field, allowing authentication to be bypassed by submitting more than 20 blank spaces. This grants an unauthenticated attacker full administrative control of the router, which is a high-impact flaw for a network edge device.
Description
login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering more than 20 blank spaces in the password field during an admin login attempt.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated admin bypass on a network edge device with public exploit code and very high EPSS, though exploitation requires adjacent network access and the CVE is not in KEV.
What it is
The login.cgi handler on D-Link DIR-600M devices running firmware 3.04 fails to properly validate the admin password field, allowing authentication to be bypassed by submitting more than 20 blank spaces. This grants an unauthenticated attacker full administrative control of the router, which is a high-impact flaw for a network edge device.
Impact
An attacker gains full administrative access to the router, enabling configuration changes, credential theft, traffic redirection, and use of the device as a pivot into the internal network.
Attack surface
The flaw is reachable over the adjacent network via the device's web management interface (login.cgi); no authentication is required and no user interaction is needed, per the CVSS vector AV:A/AC:L/PR:N/UI:N.
Exploitation
Public exploit code and proof-of-concept write-ups are referenced (Exploit-DB 42039, vendor blog, YouTube), and EPSS is very high at 0.997 percentile, though the CVE is not listed in CISA KEV.
What to do
- Apply the latest D-Link firmware for DIR-600M if a fixed release exists; if the device is end-of-life, replace it.
- Restrict access to the router's web management interface to trusted management networks only.
- Disable remote administration and WAN-side access to login.cgi.
- Change default admin credentials and monitor for unauthorized configuration changes.
- Segment or retire the device if it cannot be patched.
Detection
- Monitor router and web logs for login.cgi POST requests containing long runs of whitespace in the password parameter.
- Alert on successful admin logins from unexpected source IPs or outside management hours.
- Audit router configuration changes and new admin accounts for unauthorized modifications.
- Watch for outbound connections from the router to known malicious or unusual destinations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://touhidshaikh.com/blog/poc/d-link-dir600-auth-bypass/ | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/42039/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.youtube.com/watch?v=waIJKWCpyNQ | ExploitThird Party Advisory |
| http://touhidshaikh.com/blog/poc/d-link-dir600-auth-bypass/ | ExploitThird Party Advisory |
| https://www.exploit-db.com/exploits/42039/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.youtube.com/watch?v=waIJKWCpyNQ | ExploitThird Party Advisory |
Track CVE-2017-9100 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9100), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.