First published: Thu Dec 30 2021(Updated: )
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the "admin" user, UID 0).
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-2640-us Firmware | <=1.11b02 | |
Dlink Dir-2640-us |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.