EXPOSURES › CVE-2011-4723
CVE-2011-4723
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
exploited-in-wildunpatchedrce
D-Link DIR-300 stored passwords in plaintext, allowing attackers to access sensitive data.
The D-Link DIR-300 router stored passwords in plaintext, enabling attackers to access sensitive information. This vulnerability was actively exploited and has been linked to context-dependent attacks. DIB organizations should be concerned due to the ease of exploitation and the router's widespread use.
Shame score — Repeated RCE vulnerabilities in D-Link consumer firmware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.