CVE-2021-40655
dlink dir-605l_firmware, dlink dir-605l
Published 24 Sept 2021 · updated 17 Jun 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 16 May 2024, with a remediation deadline of 6 Jun 2024 for US federal agencies.
Required action: This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.
Description
An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page
References
- github.com/Ilovewomen/D-LINK-DIR-605/ · Exploit, Third Party Advisory
- www.dlink.com/en/security-bulletin/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40655 · US Government Resource