HIGH

CVE-2021-40655

Dlink Dir 605l Firmware 2021-09-24 CVSS v3.1
CVSS
7.5
KEV

Description

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

Summary dbcve.org

D-LINK DIR-605 B2 router firmware version 2.01MT contains an information disclosure vulnerability where an attacker can obtain valid username and password credentials by forging a POST request to the /getcfg.php page. This allows unauthenticated attackers to retrieve user authentication credentials.

Mitigation

Apply available vendor firmware patches if released; if no patch exists, consider device replacement or implement network segmentation to limit exposure to untrusted networks.

Proof of Concept

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

86.66%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE