CVE-2021-40655

HIGH KEV NUCLEI

D-LINK-DIR-605 B2 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-40655 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 16, 2024. A Nuclei detection template is also available.

Description

An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

Nuclei Templates (1)

D-Link DIR-605 - Information Disclosure
HIGHby DhiyaneshDK
FOFA: body="l_tb>DIR-605"

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.9261
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2024-05-16
VulnCheck KEV 2024-05-16
InTheWild.io 2024-05-16
ENISA EUVD EUVD-2021-27829
CWE
CWE-863
Status published
Products (1)
dlink/dir-605l_firmware 2.01mt
Published Sep 24, 2021
KEV Added May 16, 2024
Tracked Since Feb 18, 2026