CVE-2011-4723
KEVlargeCleartext Password Storage in D-Link DIR-300 Router
CISA: D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability
D-Link DIR-300 routers store passwords in cleartext rather than hashed or encrypted form (CWE-310), meaning credentials configured on the device remain readable as plaintext in its stored configuration. Triggering the flaw is context-dependent: an attacker who can obtain the router's stored configuration, for example through its management interface, a configuration backup, or direct access to the device, can read the passwords in plaintext. The attacker gains access to sensitive credentials, typically the router's administration and/or wireless passwords, which can be used to take over the device or to compromise other systems where the same passwords were reused. Only the D-Link DIR-300 is listed as affected by CISA; the model is end-of-life, so any owner still running it is exposed. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming active exploitation in the wild (ransomware use unknown), and EPSS currently estimates a 3% probability of exploitation activity in the next 30 days (86th percentile).
What to do: Because the DIR-300 is end-of-life, CISA's required action is to disconnect it if still in use; replace it with a supported router rather than expecting further firmware fixes. If replacement must be delayed, restrict management access to trusted clients, do not expose the device's web interface to the internet, and rotate any passwords configured on the device, especially ones reused elsewhere, since they are recoverable in cleartext. Audit networks for remaining DIR-300 units, particularly in internet-facing positions.
| D-Link DIR-300 Router | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information.
- Affected
- D-Link DIR-300 Router
- Required action
- The impacted product is end-of-life and should be disconnected if still in use.
- Due date
- Ransomware use
- Unknown
- Vendors
- D-Link
- Products
- DIR-300 Router
- Weakness
- CWE-310