CVE-2021-21816
D-Link DIR-3040 1.13B03 - Information Disclosure
Record summary
CVE-2021-21816 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.
Description
An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
D-LINK | CVE List | D-LINK DIR-3040 1.13B03 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMD-Link DIR-3040 1.13B03 - Information DisclosureCVSS 4.3
D-Link DIR-3040 1.13B03 is susceptible to information disclosure in the Syslog functionality. A specially crafted HTTP network request can lead to the disclosure of sensitive information. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the router, potentially leading to further attacks.
Remediation
Upgrade the router firmware to the latest version provided by D-Link.
Source: ProjectDiscovery