ZeroHour

CVE-2011-4723

KEVlarge

Cleartext Password Storage in D-Link DIR-300 Router

CISA: D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability

CVSS
EPSS
3%p87
Published
KEV added
AI analysis

D-Link DIR-300 routers store passwords in cleartext rather than hashed or encrypted form (CWE-310), meaning credentials configured on the device remain readable as plaintext in its stored configuration. Triggering the flaw is context-dependent: an attacker who can obtain the router's stored configuration, for example through its management interface, a configuration backup, or direct access to the device, can read the passwords in plaintext. The attacker gains access to sensitive credentials, typically the router's administration and/or wireless passwords, which can be used to take over the device or to compromise other systems where the same passwords were reused. Only the D-Link DIR-300 is listed as affected by CISA; the model is end-of-life, so any owner still running it is exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming active exploitation in the wild (ransomware use unknown), and EPSS currently estimates a 3% probability of exploitation activity in the next 30 days (86th percentile).

What to do: Because the DIR-300 is end-of-life, CISA's required action is to disconnect it if still in use; replace it with a supported router rather than expecting further firmware fixes. If replacement must be delayed, restrict management access to trusted clients, do not expose the device's web interface to the internet, and rotate any passwords configured on the device, especially ones reused elsewhere, since they are recoverable in cleartext. Audit networks for remaining DIR-300 units, particularly in internet-facing positions.

Affected
D-Link DIR-300 Router
Estimated exposure
large≈ hundreds of thousands of DIR-300 units still in use worldwide (order-of-magnitude estimate) — The DIR-300 was a mass-market budget router sold in the millions in the late 2000s and early 2010s and is now end-of-life, so a shrinking but still substantial installed base of home and small-office devices plausibly remains in service.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.

CISA Known Exploited Vulnerability
Affected
D-Link DIR-300 Router
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
D-Link
Products
DIR-300 Router
Weakness
CWE-310

In the news