← Vulnerability feed

Vulnerability record · CVE-2018-12710 · published 29 August 2018

CVE-2018-12710: D-Link DIR-601 router leaks admin password in XML response

Dlink · Dir 601 Firmware

On D-Link DIR-601 2.02NA devices, a low-privilege "User" account can intercept the response to a POST request and read the admin password, which is returned in XML. This exposes administrative credentials to any authenticated local user on the network, allowing full takeover of the device.

8.0 CVSS 3.0 High EPSS 77% · top 0.5% CWE-319 · Cleartext transmission
8.0CVSS 3.0 base score, v2 2.7
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.

CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw exposes admin credentials to any low-privilege local user and public exploit code exists, though it requires an authenticated account on the adjacent network.

What it is

On D-Link DIR-601 2.02NA devices, a low-privilege "User" account can intercept the response to a POST request and read the admin password, which is returned in XML. This exposes administrative credentials to any authenticated local user on the network, allowing full takeover of the device.

Impact

An attacker with a low-privilege User account gains the Admin password and can take full control of the router, including changing its configuration.

Attack surface

The flaw is reachable from the adjacent network by an attacker who holds a valid low-privilege User account; no user interaction is required, and the admin password is exposed in the XML response to a POST request.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.765, 99.5th percentile) and public exploit code exists on Exploit-DB, indicating active interest and easy exploitation.

What to do

  • Apply the latest D-Link firmware for DIR-601 2.02NA or replace the device if no fix is available.
  • Restrict network access to the router management interface to trusted administrators only.
  • Remove or disable unnecessary low-privilege User accounts and rotate the admin password.
  • Monitor and log POST requests to the router's management endpoints for unusual activity.

Detection

  • Inspect router management traffic for XML responses containing admin credentials.
  • Alert on POST requests to management endpoints from non-admin accounts.
  • Review authentication logs for User-account logins followed by admin-level configuration changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2018/Aug/45 Mailing ListThird Party Advisory
https://www.exploit-db.com/exploits/45306/ ExploitThird Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2018/Aug/45 Mailing ListThird Party Advisory
https://www.exploit-db.com/exploits/45306/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2018-12710 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2018-12710), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.