Record summary

CVE-2021-21816 has a selected CVSS score of 4.3 (medium); EIP currently links 1 Nuclei template.

Description

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

D-LINK

CVE ListD-LINK DIR-3040 1.13B03affected

Nuclei templates

1
ProjectDiscoveryMEDIUMD-Link DIR-3040 1.13B03 - Information DisclosureCVSS 4.3

D-Link DIR-3040 1.13B03 is susceptible to information disclosure in the Syslog functionality. A specially crafted HTTP network request can lead to the disclosure of sensitive information. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the router, potentially leading to further attacks.

Remediation

Upgrade the router firmware to the latest version provided by D-Link.

WeaknessesCWE-200
Authorsgy741
Template tagscve2021cvedlinkexposureroutersyslogvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CPE: cpe:2.3:o:dlink:dir-3040_firmware:1.13b03:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2