important · Wi-Fi routers — D-Link
A planted cookie can inherit a D-Link administrator's authenticated session.
Affects
D-Link DIR-600 B5 embedded Wi-Fi routers running the tested legacy firmware.
An unauthenticated CRLF injection through /session.cgi can plant a chosen uid cookie; if the administrator processes that response and then logs in, the uid can be reused from another client.
Detail and 1 source
No patch is published for the demonstrated DIR-600 path.