CVE-2021-40655 vulnerability in D-Link Products
Published on September 24, 2021
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
Known Exploited Vulnerability
This D-Link DIR-605 Router Information Disclosure Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page. .
The following remediation steps are recommended / required by June 6, 2024: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Vulnerability Analysis
CVE-2021-40655 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2021-40655 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2021-40655
stack.watch emails you whenever new vulnerabilities are published in D-Link Dir 605l Firmware or D-Link Dir 605l. Just hit a watch button to start following.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.