Skip to finding
important · Wi-Fi routers — D-Link

A planted cookie can inherit a D-Link administrator's authenticated session.

Affects

D-Link DIR-600 B5 embedded Wi-Fi routers running the tested legacy firmware.

An unauthenticated CRLF injection through /session.cgi can plant a chosen uid cookie; if the administrator processes that response and then logs in, the uid can be reused from another client.

Detail and 1 source

No patch is published for the demonstrated DIR-600 path.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 23, 2026