CVE-2021-21819: OS Command Injection
Published Jul 16, 2021
·Updated
A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Affected Software
2 affected components
Dlink Dir-3040 Firmware=1.13b03
Dlink DIR-3040
Event History
Jul 16, 2021
CVE Published
via MITRE·10:24 AM
Data Sourced
via MITRE·10:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this code execution vulnerability?
The vulnerability ID is CVE-2021-21819.
2
What is the severity rating of CVE-2021-21819?
The severity rating of CVE-2021-21819 is critical with a score of 7.2.
3
Which software is affected by this vulnerability?
The D-LINK DIR-3040 version 1.13B03 firmware is affected by this vulnerability.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially crafted network request that can lead to arbitrary command execution.
5
Is there any reference or additional information about this vulnerability?
Yes, you can find more information about CVE-2021-21819 at the following reference link: https://talosintelligence.com/vulnerability_reports/TALOS-2021-1284