CVE-2021-3708
HIGH EXPLOITEDD-Link router DSL-2750U <vME1.16 - Command Injection
Title source: llmDescription
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticated attacker on the local network may exploit this, with CVE-2021-3707, to execute any OS commands on the vulnerable device.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
https://github.com/HadiMed/firmware-analysis/blob/main/DSL-2750U%20%28firmware%20version%201.6%29/README.md
Vendor Advisory x_refsource_confirm
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10230
Third Party Advisory third-party-advisory
x_refsource_jvn
https://jvn.jp/en/vu/JVNVU92088210/
Scores
CVSS v3
7.8
EPSS
0.1711
EPSS Percentile
95.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2023-12-19
CWE
CWE-78
Status
published
Products (1)
dlink/dsl-2750u_firmware
< 1.16
Published
Aug 16, 2021
Tracked Since
Feb 18, 2026