TROYANOSYVIRUS
Volver a CVEs

CVE-2021-42627

CRITICAL
9.8

Descripcion

The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/23/2022
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

dlink:dir-615dlink:dir-615_firmwaredlink:dir-615_j1dlink:dir-615_j1_firmwaredlink:dir-615_t1dlink:dir-615_t1_firmwaredlink:dir-615jx10dlink:dir-615jx10_firmware

Referencias

http://d-link.com(cve@mitre.org)
http://dlink.com(cve@mitre.org)
http://d-link.com(af854a3a-2127-422b-91ae-364da2661108)
http://dlink.com(af854a3a-2127-422b-91ae-364da2661108)
https://www.dlink.com/en/security-bulletin/(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.