Vulnerability record · CVE-2018-12710 · published 29 August 2018
CVE-2018-12710: D-Link DIR-601 router leaks admin password in XML response
Dlink · Dir 601 Firmware
On D-Link DIR-601 2.02NA devices, a low-privilege "User" account can intercept the response to a POST request and read the admin password, which is returned in XML. This exposes administrative credentials to any authenticated local user on the network, allowing full takeover of the device.
Description
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw exposes admin credentials to any low-privilege local user and public exploit code exists, though it requires an authenticated account on the adjacent network.
What it is
On D-Link DIR-601 2.02NA devices, a low-privilege "User" account can intercept the response to a POST request and read the admin password, which is returned in XML. This exposes administrative credentials to any authenticated local user on the network, allowing full takeover of the device.
Impact
An attacker with a low-privilege User account gains the Admin password and can take full control of the router, including changing its configuration.
Attack surface
The flaw is reachable from the adjacent network by an attacker who holds a valid low-privilege User account; no user interaction is required, and the admin password is exposed in the XML response to a POST request.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.765, 99.5th percentile) and public exploit code exists on Exploit-DB, indicating active interest and easy exploitation.
What to do
- Apply the latest D-Link firmware for DIR-601 2.02NA or replace the device if no fix is available.
- Restrict network access to the router management interface to trusted administrators only.
- Remove or disable unnecessary low-privilege User accounts and rotate the admin password.
- Monitor and log POST requests to the router's management endpoints for unusual activity.
Detection
- Inspect router management traffic for XML responses containing admin credentials.
- Alert on POST requests to management endpoints from non-admin accounts.
- Review authentication logs for User-account logins followed by admin-level configuration changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://seclists.org/fulldisclosure/2018/Aug/45 | Mailing ListThird Party Advisory |
| https://www.exploit-db.com/exploits/45306/ | ExploitThird Party AdvisoryVDB Entry |
| http://seclists.org/fulldisclosure/2018/Aug/45 | Mailing ListThird Party Advisory |
| https://www.exploit-db.com/exploits/45306/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-12710 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-12710), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.