HIGH
CVE-2021-40655
CVSS
7.5
KEV
Description
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
Summary dbcve.org
D-LINK DIR-605 B2 router firmware version 2.01MT contains an information disclosure vulnerability where an attacker can obtain valid username and password credentials by forging a POST request to the /getcfg.php page. This allows unauthenticated attackers to retrieve user authentication credentials.
Mitigation
Apply available vendor firmware patches if released; if no patch exists, consider device replacement or implement network segmentation to limit exposure to untrusted networks.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
86.66%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.