Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-17525 — D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1 | Kitploit
Tools/GitHubGitHub/huzaifahussain98/cve-2019-17525
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingCAPTCHA Bypass
GitHubhuzaifahussain98/cve-2019-17525

CVE-2019-17525

D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1

View Repository
176 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-17525

D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1

A vulnerability found on login-in page of D-LINK ROUTER "DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1" which allows attackers to easily bypass CAPTCHA on login page by BRUTEFORCING.

TARGET

"Log-in page" of D-LINK ROUTER "MODEL NO: DIR-615" with "FIRMWARE VERSION:20.10" & "HARDWARE VERSION:T1"(IP Address of router login).

ATTACK SCENARIO AND REPRODUCTION STEPS

  1. Find the PUBLIC IP of the TARGET NETWORK.
  2. On browsing the Target IP in the browser, we will get a ROUTER LoginPage.
  3. Fill the required login credentials.
  4. Fill the CAPTCH properly and Intercept the request in Burpsuit.
  5. Send the Request to Intruder and select the target variables i.e. username & password which will we bruteforce under Positions Tab
  6. Set the payloads on target variables i.e. username & password under Payloads Tab.
  7. Set errors in (the validatecode is invalid & username or password error, try again) GREP-MATCH under Options Tab.
  8. Now hit the start attack and you will find the correct credentials.

REGARDS

Huzaifa Hussain

https://twitter.com/disguised_noob

https://www.linkedin.com/in/huzaifa-hussain-046791179

Download Tool