CVE-2021-40654: Medium severity Dlink Dir-615 Firmware vulnerability
Published Sep 24, 2021
·Updated
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
Affected Software
4 affected components
Dlink Dir-615 Firmware=17.00
Dlink Dir-615=q1
All of the following
Dlink Dir-615 Firmware=17.00
Dlink Dir-615=q1
Event History
Sep 24, 2021
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-40654?
The severity of CVE-2021-40654 is medium with a severity value of 6.5.
2
How can an attacker exploit CVE-2021-40654?
An attacker can exploit CVE-2021-40654 by forging a post request to the /getcfg.php page to obtain a user name and password.
3
What software is affected by CVE-2021-40654?
The D-LINK-DIR-615 B2 2.01mt firmware version 17.00 is affected by CVE-2021-40654.
4
Is the D-Link DIR-615 Q1 version vulnerable to CVE-2021-40654?
No, the D-Link DIR-615 Q1 version is not vulnerable to CVE-2021-40654.
5
Are there any references for CVE-2021-40654?
Yes, you can find references for CVE-2021-40654 at https://github.com/Ilovewomen/D-LINK-DIR-615 and https://www.dlink.com/en/security-bulletin/