CVE-2018-25358

D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST requests. Attackers can send requests to /my_cgi.cgi with table_name values like admin_user, wireless_settings, and wireless_security to extract administrative credentials and wireless network keys in clear text.
Configurations

No configuration.

History

23 May 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-23 19:16

Updated : 2026-05-26 20:16


NVD link : CVE-2018-25358

Mitre link : CVE-2018-25358

CVE.ORG link : CVE-2018-25358


JSON object : View

Products Affected

No product.

CWE
CWE-497

Exposure of Sensitive System Information to an Unauthorized Control Sphere