The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.
2013-10-19T10:36:08.963
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Hardware | dlink | di-524up | - | Yes |
Hardware | dlink | di-604\+ | - | Yes |
Hardware | dlink | di-604s | - | Yes |
Hardware | dlink | di-604up | - | Yes |
Hardware | dlink | di-624s | - | Yes |
Hardware | dlink | dir-100 | - | Yes |
Hardware | dlink | dir-120 | - | Yes |
Hardware | dlink | tm-g5240 | - | Yes |
Hardware | alphanetworks | vdsl_asl-55052 | - | Yes |
Hardware | alphanetworks | vdsl_asl-56552 | - | Yes |
Hardware | planex | brl-04cw | - | Yes |
Hardware | planex | brl-04r | - | Yes |
Hardware | planex | brl-04ur | - | Yes |