CVE-2013-6026
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.
Published:Oct 19, 2013
Last Modified:Apr 11, 2025
EPS:Oct 19, 2013
EPSS Score:0.11409
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Alphanetworks
Product
Vdsl Asl-55052
Alphanetworks
Vdsl Asl-55052
Vendor
Alphanetworks
Product
Vdsl Asl-56552
Alphanetworks
Vdsl Asl-56552
Vendor
Dlink
Product
Di-524up
Dlink
Di-524up
Vendor
Dlink
Product
Di-604\+
Dlink
Di-604\+
Vendor
Dlink
Product
Di-604s
Dlink
Di-604s
Vendor
Dlink
Product
Di-604up
Dlink
Di-604up
Vendor
Dlink
Product
Di-624s
Dlink
Di-624s
Vendor
Dlink
Product
Dir-100
Dlink
Dir-100
Vendor
Dlink
Product
Dir-120
Dlink
Dir-120
Vendor
Dlink
Product
Tm-g5240
Dlink
Tm-g5240
Vendor
Planex
Product
Brl-04cw
Planex
Brl-04cw
Vendor
Planex
Product
Brl-04r
Planex
Brl-04r
Vendor
Planex
Product
Brl-04ur
Planex
Brl-04ur
Exploits
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
