CVE-2013-6026

UnknownEPSS 7.68%

Last modified

CVE-2013-6026 is a vulnerability of currently unknown severity. The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.. EPSS estimates a 7.68% chance of exploitation in the next 30 days.

Description

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.

Metrics

EPSS Probability
7.68%

93.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DlinkDi-524upAll versions
DlinkDi-604\+All versions
DlinkDi-604sAll versions
DlinkDi-604upAll versions
DlinkDi-624sAll versions
DlinkDir-100All versions
DlinkDir-120All versions
DlinkTm-G5240All versions
AlphanetworksVdsl Asl-55052All versions
AlphanetworksVdsl Asl-56552All versions
PlanexBrl-04cwAll versions
PlanexBrl-04rAll versions
PlanexBrl-04urAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2013-6026?
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.
How severe is CVE-2013-6026?
Severity scoring for CVE-2013-6026 is pending analysis. The EPSS model estimates a 7.68% probability of exploitation in the next 30 days.
How do I fix CVE-2013-6026?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2013-6026?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST