CVE-2021-40655: D-Link DIR-605 Router Information Disclosure Vulnerability
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
Other sources
D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40655?
CVE-2021-40655 is an information disclosure issue in D-LINK-DIR-605 B2 Firmware Version 2.01MT, allowing an attacker to obtain a username and password by forging a post request to the /getcfg.php page.
What software is affected by CVE-2021-40655?
Dlink Dir-605l Firmware version 2.01MT is affected by CVE-2021-40655.
How severe is CVE-2021-40655?
CVE-2021-40655 has a severity rating of 7.5, which is considered high.
How can an attacker exploit CVE-2021-40655?
An attacker can exploit CVE-2021-40655 by forging a post request to the /getcfg.php page to obtain a user name and password.
Is there a patch or fix available for CVE-2021-40655?
The D-LINK-DIR-605 B2 Firmware version 2.01MT may have a fix or patch available. Please refer to the vendor's security bulletin for more information.