Vulnerability record · CVE-2019-13101 · published 8 August 2019
CVE-2019-13101: D-Link DIR-600M wan.htm missing authentication exposes and alters WAN settings
Dlink · Dir 600m Firmware
The D-Link DIR-600M router firmware (versions 3.02, 3.03, 3.04, 3.06) allows the wan.htm page to be accessed directly without authentication. This missing authentication for a critical function lets anyone reach the WAN configuration page, exposing WAN information and permitting modification of its data fields.
Description
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 3.1 base score is 9.8 (critical) with no authentication or user interaction required, and EPSS is very high at 0.67091, though the device is end-of-life and not in KEV.
What it is
The D-Link DIR-600M router firmware (versions 3.02, 3.03, 3.04, 3.06) allows the wan.htm page to be accessed directly without authentication. This missing authentication for a critical function lets anyone reach the WAN configuration page, exposing WAN information and permitting modification of its data fields.
Impact
An unauthenticated attacker can read WAN-related information and change WAN configuration fields on the device, potentially disrupting or redirecting the router's internet connectivity and settings.
Attack surface
Reachable over the network via HTTP to the router's wan.htm page; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and description confirm no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented; EPSS is high at 0.67091 (99.266th percentile), and references are advisories and mailing-list disclosures rather than exploit code.
What to do
- Apply the vendor firmware fix or security advisory guidance from D-Link; if no fixed firmware exists for the affected versions, replace or retire the device.
- Restrict router management access to trusted internal networks and disable remote/WAN-side administration.
- Segment IoT and router management traffic from general user networks and block inbound access to the device's web interface.
- Change default administrative credentials and monitor for unauthorized configuration changes.
- If the device cannot be patched or isolated, take it out of service.
Detection
- Monitor HTTP requests to /wan.htm on D-Link DIR-600M devices, especially from untrusted or external sources.
- Alert on configuration changes to WAN settings made outside approved maintenance windows.
- Audit router logs for unauthenticated access to management pages and unexpected source IPs.
- Scan internal networks for exposed D-Link DIR-600M management interfaces reachable from untrusted segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-13101 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-13101), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.