First published: Fri Sep 24 2021(Updated: )
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dlink Dir-605l Firmware | =2.01mt | |
Dlink Dir-605l | =b2 | |
All of | ||
Dlink Dir-605l Firmware | =2.01mt | |
Dlink Dir-605l | =b2 | |
D-Link DIR-605 router | ||
All of | ||
=2.01mt | ||
=b2 |
This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40655 is an information disclosure issue in D-LINK-DIR-605 B2 Firmware Version 2.01MT, allowing an attacker to obtain a username and password by forging a post request to the /getcfg.php page.
Dlink Dir-605l Firmware version 2.01MT is affected by CVE-2021-40655.
CVE-2021-40655 has a severity rating of 7.5, which is considered high.
An attacker can exploit CVE-2021-40655 by forging a post request to the /getcfg.php page to obtain a user name and password.
The D-LINK-DIR-605 B2 Firmware version 2.01MT may have a fix or patch available. Please refer to the vendor's security bulletin for more information.