Description
A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attack can be initiated remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
Timeline
| 2026-04-30: | Advisory disclosed |
| 2026-04-30: | VulDB entry created |
| 2026-04-30: | VulDB entry last update |
Credits
iam0range (VulDB User)
References
vuldb.com/vuln/360362 (VDB-360362 | D-Link M60 httpd password recovery)
vuldb.com/vuln/360362/cti (VDB-360362 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/805642 (Submit #805642 | https://www.dlink.com/ M60 AX6000 Wi-Fi 6 Smart Mesh Router Firmware: V1.20B02 Translation Authentication Bypass + Encrypted Integrity Check By)
www.yuque.com/iam0range/rle72q/dhs1zsbgtm1ne0y1
www.dlink.com/