First published: Fri Sep 24 2021(Updated: )
An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-615 Firmware | =17.00 | |
Dlink Dir-615 | =q1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-40654 is medium with a severity value of 6.5.
An attacker can exploit CVE-2021-40654 by forging a post request to the /getcfg.php page to obtain a user name and password.
The D-LINK-DIR-615 B2 2.01mt firmware version 17.00 is affected by CVE-2021-40654.
No, the D-Link DIR-615 Q1 version is not vulnerable to CVE-2021-40654.
Yes, you can find references for CVE-2021-40654 at https://github.com/Ilovewomen/D-LINK-DIR-615 and https://www.dlink.com/en/security-bulletin/