Junglewise Threat Intelligence

CVE-2021-40655: D-Link DIR-605 Router Information Disclosure Vulnerability

CVE-2021-40655 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-05-16

Vendors: D-Link.

Executive brief

D-Link DIR-605 routers contain an information disclosure vulnerability due to incorrect authorization. An attacker can obtain the device's username and password by sending a forged POST request to the /getcfg.php page.

Affected products

  • D-Link DIR-605 B2 Firmware 2.01MT
  • D-Link DIR-605L B2 Firmware 2.01MT

Timeline

  • 2021-09-24: disclosed: NVD Published Date
  • 2024-05-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-05-16: exploited: CISA confirmed exploitation in the wild