D-Link routers and Good Line Router v2 disclose information through HTTP GET /devinfo

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2024-0717?

CVE-2024-0717 is a vulnerability classified as Exposure of Sensitive Information to an Unauthorized Actor, affecting DAP-1360 (affected versions: 20240112), DIR-300 (affected versions: 20240112), DIR-615 (affected versions: 20240112), and 42 more products. This vulnerability is rated Medium, with a CVSS score of 5.3. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Overview

Original source data

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1, DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860, DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR, DVG-5402G, DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, DWR-953 and Good Line Router v2 up to 20240112. This vulnerability affects unknown code of the file /devinfo of the component HTTP GET Request Handler. The manipulation of the argument area with the input notice|net|version leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-251542 is the identifier assigned to this vulnerability.

Affected products and scope

The normalized record marks version 20240112 as affected for the models below. The CNA description presents the scope as the listed models up to 20240112; no fixed release is confirmed.

  • D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, DIR-825AC, DIR-825ACF, DIR-825ACG1.
  • D-Link DIR-841, DIR-842, DIR-842S, DIR-843, DIR-853, DIR-878, DIR-882, DIR-1210, DIR-1260, DIR-2150, DIR-X1530, DIR-X1860.
  • D-Link DSL-224, DSL-245GR, DSL-2640U, DSL-2750U, DSL-G2452GR.
  • D-Link DVG-5402G, DVG-5402GFRU, DVG-N5402G, DVG-N5402G-IL, DWM-312W, DWM-321, DWR-921, and DWR-953.
  • Good Line Router v2.

Other models, firmware branches, or devices outside this list are not established as affected by the available record.

Technical details

D-Link routers and Good Line Router v2 contain an information disclosure flaw in the HTTP GET Request Handler, involving the /devinfo file or interface. The technical description states that the area argument is controllable and that the value notice|net|version causes the handler to return device information. The record confirms remote reachability without authentication or user interaction; the exact internal implementation and complete response data remain undisclosed.

The public report describes possible response fields including the model, version, MAC address, IP address, routing information, and device region. These fields are reported examples, not evidence that every model returns the same set of data.

Exploitability

The flaw can be reached over the network by sending an HTTP request to the /devinfo interface on an affected device. The record describes exploitation as requiring no authentication, no user interaction, and low complexity. A public proof of concept has been disclosed, so exploitation is not merely theoretical. The available evidence confirms public exploit availability but does not identify an organized campaign or confirmed in-the-wild exploitation.

Technical impact

When exploited, the HTTP GET Request Handler can return information from the /devinfo interface to a remote requester without authentication. The confirmed outcome is information disclosure, with the primary effect on the confidentiality of device data.

The disclosed information may include model and version data, along with other device or network fields described in the public report. This may help an attacker fingerprint the device and prepare follow-on activity, but the current record does not establish configuration modification, privilege escalation, code execution, or availability impact. The direct scope is the device processing the request unless the exposed information is used in a separate attack.

Business impact

The flaw can expose device identity and network-state information, such as the model, version, MAC address, IP address, routing information, or device region when those fields are returned.

  • The exposed metadata may support fingerprinting, asset enumeration, and selection of targets for subsequent attacks.
  • Operations teams may need to review a broad set of older router models, restrict management access, and replace devices for which no confirmed fix is available.
  • The available evidence confirms an impact to information confidentiality. It does not establish that the flaw itself permits configuration changes, code execution, or service disruption.

Remediation

  1. Identify and prioritize every listed device running version 20240112.
  2. No fixed release or official patch is confirmed by the available evidence. Contact D-Link or the device provider to verify supported firmware for the exact model before deploying an update.
  3. Until a supported fix is confirmed, restrict the HTTP management interface to trusted administration networks, remove WAN access if the device supports that control, and place authentication or an access-control layer in front of /devinfo. These are compensating controls, not a confirmed vendor fix.
  4. If a supported patch or reliable access-control mitigation is unavailable, plan to replace the device. Do not treat an unverified firmware version as proof that the vulnerability has been fixed.

Detection

  1. Inventory D-Link and Good Line Router v2 devices, recording the exact model, firmware, and exposure of the HTTP management interface.
  2. Compare each model with the affected list and check whether the firmware reports version 20240112.
  3. Review which networks can reach the HTTP management interface, especially whether it is reachable from the WAN or other untrusted networks.
  4. If HTTP access logs are retained, look for requests to /devinfo and related area values such as notice, net, or version. The absence of matching logs does not prove that a device is safe because logging may be disabled or overwritten.
  5. If responses containing model, version, MAC, IP, routing, or region information appear outside expected administration activity, investigate the source and timing of the requests.
Sources (22)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan