CVE-2011-4723
D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability
Description
CVE-2011-4723 is a cleartext storage of password vulnerability in the D-Link DIR-300 router that allows context-dependent attackers to obtain sensitive authentication information. The router stores administrator passwords in cleartext within its configuration files, making them accessible to anyone who can read the device's configuration. This is a fundamental security design flaw that exposes all users of the affected router to credential theft. CISA has added CVE-2011-4723 to its Known Exploited Vulnerabilities catalog, and with an EPSS score of 12.7% (94th percentile), the vulnerability continues to be targeted despite the device being end-of-life.
KEV Information
CVSS Score
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| dlink | dir-300 firmware | - |
References
- http://en.securitylab.ru/lab/PT-2011-30(Broken Link)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2011-4723(US Government Resource)
Weakness Type
CWE-312: Cleartext Storage of Sensitive Information
CVE-2011-4723 exploits a cleartext storage of sensitive information weakness in the D-Link DIR-300 router, where administrator passwords are stored without any form of encryption or hashing in the device's configuration files. This means that any attacker who can access the configuration — whether through a configuration backup, a separate vulnerability, or physical access — can immediately read the administrator credentials in plaintext.
Learn more: CWE-312 — Cleartext Storage of Sensitive Information
Impact Analysis
CVE-2011-4723 presents a significant risk for environments where D-Link DIR-300 routers are still in use. The cleartext password storage means that any vector providing access to the device's configuration data — including configuration backup downloads, path traversal vulnerabilities, or physical access to the device — immediately yields the administrator password. Once obtained, the password grants full control over the router, enabling DNS hijacking, traffic interception, firewall modification, and use of the device as a network pivot point. With an EPSS score of 12.7% (94th percentile), exploitation activity remains elevated despite the age of the vulnerability, reflecting the continued presence of these devices in operational networks. The D-Link DIR-300 is an end-of-life product that will not receive security updates, meaning this vulnerability will never be patched.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2011-4723 in the wild by adding it to the Known Exploited Vulnerabilities catalog. The EPSS score of 12.7% (94th percentile) indicates significant ongoing exploitation activity despite the vulnerability being over a decade old. The trivial nature of the exploit — simply reading cleartext passwords from configuration files — means no specialized tools are required. The D-Link DIR-300 is end-of-life and will receive no further security updates, making the only effective mitigation complete device replacement. No specific ransomware campaigns are currently associated with this CVE.
Remediation
- Disconnect and replace the D-Link DIR-300: Per the CISA KEV required action, the impacted product is end-of-life and should be disconnected if still in use. Replace it with a currently supported router that properly hashes and protects stored credentials.
- Do not reuse the DIR-300 administrator password: If the DIR-300 administrator password was used on any other device or service, change it immediately on all systems where it was reused, as it may have already been extracted from the device.
- Audit network for end-of-life devices: Conduct a comprehensive inventory of all network equipment and identify any other end-of-life devices that may have similar security weaknesses, replacing them proactively.
- Implement network segmentation: Until the DIR-300 can be replaced, isolate it from sensitive network segments and monitor traffic to and from the device for suspicious activity.
- Use credential management best practices: On replacement devices, use unique, complex administrator passwords and enable credential hashing where available. Implement centralized network device management with proper credential storage.
Technical Details
CVE-2011-4723 is a cleartext credential storage vulnerability in the D-Link DIR-300 wireless router. The device stores the administrator password in its configuration files without applying any cryptographic protection — no hashing, no encryption, and no salting. When an attacker obtains access to the configuration data, whether through a configuration export feature, a separate vulnerability that allows file read access, or physical extraction of the device's flash memory, the administrator password is immediately readable in plaintext. This represents a fundamental violation of secure credential storage practices, where passwords should always be stored using strong one-way hash functions with unique salts. The DIR-300's configuration format makes the password trivially extractable, and since the device has reached end-of-life, D-Link will not release a firmware update to address this design flaw.
Frequently Asked Questions
Is CVE-2011-4723 being actively exploited?
Yes. CISA has added CVE-2011-4723 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Despite being over a decade old, the EPSS score of 12.7% (94th percentile) indicates significant ongoing exploitation activity. The D-Link DIR-300 is end-of-life and will not be patched.
What products are affected by CVE-2011-4723?
CVE-2011-4723 specifically affects the D-Link DIR-300 wireless router. This consumer-grade router stores administrator passwords in cleartext in its configuration files. The device has reached end-of-life and no firmware updates will be released.
How do I fix CVE-2011-4723?
The only effective fix is to replace the D-Link DIR-300 with a currently supported router, as the device is end-of-life and will not receive security updates. CISA explicitly recommends disconnecting the device if still in use. Do not reuse the DIR-300 administrator password on any other systems.
How severe is CVE-2011-4723?
CVE-2011-4723 is a significant credential exposure vulnerability that allows trivial extraction of administrator passwords from the D-Link DIR-300. With an EPSS score of 12.7% (94th percentile), it remains actively targeted. Because the device is end-of-life with no available patches, the vulnerability poses a permanent risk for any environment still using this router.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.