Record summary

CVE-2021-42627 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALD-Link DIR-615 - Unauthorized AccessCVSS 9.8

D-Link DIR-615 devices with firmware 20.06 are susceptible to unauthorized access. An attacker can access the WAN configuration page wan.htm without authentication, which can lead to disclosure of WAN settings, data modification, and/or other unauthorized operations.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to the router, potentially compromising the network and exposing sensitive information.

Remediation

Apply the latest firmware update provided by D-Link to fix the vulnerability and ensure strong and unique passwords are set for router administration.

AuthorsFor3stCo1d
Template tagscve2021cved-linkrouterunauthdir-615roteadordlinkvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:dlink:dir-615:-:*:*:*:*:*:*:*
Shodan: http.title:"Roteador Wireless"
Shodan: cpe:"cpe:2.3:h:dlink:dir-615"

Source: ProjectDiscovery

References

5